PT-2025-30618 · Gnu +1 · Gnu C Library +1

Published

2025-07-23

·

Updated

2025-07-23

·

CVE-2025-8058

CVSS v4.0
5.9
VectorAV:L/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H

Name of the Vulnerable Software and Affected Versions:

GNU C Library versions 2.4 through 2.41

Description:

The `regcomp` function is subject to a double free if a previous allocation fails. This can occur due to a `malloc` failure or through the use of an interposed `malloc` that introduces allocation failures. The double free can potentially allow buffer manipulation depending on the construction of the regular expression. This issue affects all supported architectures and ABIs.

Recommendations:

Versions prior to 2.41 are recommended.

Fix

Double Free

Weakness Enumeration

Related Identifiers

CVE-2025-8058

Affected Products

Debian
Gnu C Library