PT-2026-3558 · Gnu+4 · Gnu C Library+4
Vitaly Simonovich
·
Published
2025-01-01
·
Updated
2026-05-05
·
CVE-2025-15281
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
GNU C Library versions 2.0 through 2.42
Description
Using the
wordexp function with WRDE REUSE and WRDE APPEND together in the GNU C Library can lead to the function returning uninitialized memory in the we wordv member. Subsequent calls to wordfree may then cause the process to terminate.Recommendations
Avoid using
WRDE REUSE in conjunction with WRDE APPEND when calling the wordexp function.Fix
DoS
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gnu C Library
Linuxmint
Red Os
Rocky Linux
Ubuntu