CVE-2025-15614

NameCVE-2025-15614
Descriptionugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated heap buffer, potentially crashing the process.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ugrep (PTS)bookworm3.11.2+dfsg-1vulnerable
trixie7.4.2+dfsg-1vulnerable
forky, sid7.8.2+dfsg-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ugrepsource(unstable)7.6.0+dfsg-1unimportant

Notes

https://github.com/Genivia/ugrep/issues/511
Fixed by: https://github.com/Genivia/ugrep/commit/c12849a11264e2c81c860bf78ee9039772f307a4 (v7.6.0)
Crash in CLI tool, no security impact

Search for package or bug name: Reporting problems