CVE-2025-71263

In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' variable having a fixed size of 100 bytes. A local user can exploit this to gain root privileges. It is unlikely that UNIX v4 is running anywhere outside of a very small number of lab environments. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Configurations

Configuration 1 (hide)

cpe:2.3:o:opengroup:unix:4:*:*:*:*:*:*:*

History

11 Jun 2026, 21:09

Type Values Removed Values Added
References () https://discuss.systems/@ricci/115747843169814700 - () https://discuss.systems/@ricci/115747843169814700 - Issue Tracking
References () https://sigma-star.at/blog/2025/12/unix-v4-buffer-overflow/ - () https://sigma-star.at/blog/2025/12/unix-v4-buffer-overflow/ - Press/Media Coverage
References () https://www.spinellis.gr/blog/20251223/ - () https://www.spinellis.gr/blog/20251223/ - Technical Description
References () https://www.tuhs.org/pipermail/tuhs/2026-January/032991.html - () https://www.tuhs.org/pipermail/tuhs/2026-January/032991.html - Issue Tracking, Mailing List
References () http://www.openwall.com/lists/oss-security/2026/03/20/6 - () http://www.openwall.com/lists/oss-security/2026/03/20/6 - Issue Tracking, Mailing List
References () http://www.openwall.com/lists/oss-security/2026/03/21/4 - () http://www.openwall.com/lists/oss-security/2026/03/21/4 - Issue Tracking, Mailing List
First Time Opengroup unix
Opengroup
CPE cpe:2.3:o:opengroup:unix:4:*:*:*:*:*:*:*

21 Mar 2026, 22:16

Type Values Removed Values Added
Summary (en) In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' variable having a fixed size of 100 bytes. A local user can exploit this to gain root privileges. It is unlikely that UNIX v4 is running anywhere outside of a very small number of lab environments. (en) In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' variable having a fixed size of 100 bytes. A local user can exploit this to gain root privileges. It is unlikely that UNIX v4 is running anywhere outside of a very small number of lab environments. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

21 Mar 2026, 19:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/03/21/4 -

21 Mar 2026, 02:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/03/20/6 -
Summary
  • (es) En UNIX Cuarta Edición de Investigación (v4), el comando su es vulnerable a un desbordamiento de búfer debido a que la variable 'password' tiene un tamaño fijo de 100 bytes. Un usuario local puede explotar esto para obtener privilegios de root. Es poco probable que UNIX v4 se esté ejecutando en algún lugar fuera de un número muy reducido de entornos de laboratorio.

13 Mar 2026, 19:53

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-13 19:53

Updated : 2026-06-11 21:09


NVD link : CVE-2025-71263

Mitre link : CVE-2025-71263

CVE.ORG link : CVE-2025-71263


JSON object : View

Products Affected

opengroup

  • unix
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')