Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-15281

Опубликовано: 20 янв. 2026
Источник: debian

Описание

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glibcfixed2.42-11package
glibcno-dsatrixiepackage
glibcno-dsabookwormpackage
glibcpostponedbullseyepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2026/01/20/3

  • Introduced with: https://sourceware.org/git/?p=glibc.git;a=commit;h=8f2ece695d8822e9ecc63ecd157e90bf17a6fe65 (glibc-2.0.92)

  • Fixed by: https://sourceware.org/git/?p=glibc.git;a=commit;h=80cc58ea2de214f85b0a1d902a3b668ad2ecb302 (glibc-2.43)

Связанные уязвимости

CVSS3: 7.5
ubuntu
18 дней назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

CVSS3: 7.5
nvd
18 дней назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

CVSS3: 7.5
github
18 дней назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

suse-cvrf
4 дня назад

Security update for glibc

suse-cvrf
9 дней назад

Security update for glibc