Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2025-15281

Опубликовано: 21 янв. 2026
Источник: msrc
CVSS3: 6.2
EPSS Низкий

Описание

wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

EPSS

Процентиль: 20%
0.00066
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

CVSS3: 5.9
redhat
2 месяца назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

CVSS3: 7.5
nvd
2 месяца назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

CVSS3: 7.5
debian
2 месяца назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the ...

CVSS3: 7.5
github
2 месяца назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

EPSS

Процентиль: 20%
0.00066
Низкий

6.2 Medium

CVSS3