CVE-2025-71263

Publication date

2026-03-13 18:38:07

Family

mitre

State

PUBLISHED

Description

In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the password variable having a fixed size of 100 bytes. A local user can exploit this to gain root privileges. It is unlikely that UNIX v4 is running anywhere outside of a very small number of lab environments.