Researchers analyzing a recently recovered Bell Labs Research Unix Version 4 source tree found a buffer overflow in /bin/su, the privilege-switching utility shipped with the 1973-era system. The flaw is in su.c, which stores password input in a 100-character buffer but reads characters without enforcing a length limit, allowing input to write past the end of the buffer. The issue was assigned CVE-2025-71263 and was highlighted on the oss-sec mailing list by Alan Coopersmith.
The vulnerability surfaced after users began running the recovered UNIX v4 software in PDP-11 simulators and reviewing its source code. Follow-up discussion on oss-sec noted that the affected platform is largely of historical interest, with some participants questioning the practical value of assigning a CVE to such an old system, but the reported bug remains a documented memory-safety flaw in a recovered legacy UNIX release.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
The buffer overflow in /bin/su from recovered UNIX v4 was assigned CVE-2025-71263. Subsequent mailing list discussion questioned the practical relevance of assigning a CVE to a largely historical system.
Analysis of UNIX v4's su.c found that it uses a 100-character password buffer but reads password input without boundary checks, allowing writes past the end of the buffer in /bin/su.
A 1973 Bell Labs Research Unix Version 4 release was recently recovered from tape, and researchers began running the software in PDP-11 simulators and analyzing its source code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.