VDB

DEBIAN-CVE-2025-15281

DEBIAN-CVE-2025-15281 PUBLISHED CVSS 7.5 HIGH

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Debian:11glibc*, 2.33-2, 2.33-2
Debian:14glibc2.41-12, 2.42-10, 2.42-2
Debian:13glibc0, 2.41-12, *
Debian:12glibc2.39-7, 2.39-7+sh4, 2.39-8~0

Timeline

  • Jan 20, 2026 CVE Published
  • May 16, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›