Skip to main content

CVE-2025-14104

CVE Details

Visit the official vulnerability details page for CVE-2025-14104 to learn more.

Initial Publication

12/05/2025

Last Update

02/17/2026

Third Party Dependency

libblkid

NIST CVE Summary

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

CVE Severity

6.1

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Awaiting Analysis

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
0.7.1⚠️ Impacted⚠️ Impacted
0.6.6⚠️ Impacted⚠️ Impacted
0.5.11⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.