Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qg56-4cfq-w9w3

Опубликовано: 20 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

EPSS

Процентиль: 20%
0.00066
Низкий

7.5 High

CVSS3

Дефекты

CWE-908

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

CVSS3: 5.9
redhat
2 месяца назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

CVSS3: 7.5
nvd
2 месяца назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

CVSS3: 6.2
msrc
2 месяца назад

wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

CVSS3: 7.5
debian
2 месяца назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the ...

EPSS

Процентиль: 20%
0.00066
Низкий

7.5 High

CVSS3

Дефекты

CWE-908