Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-15281

Опубликовано: 20 янв. 2026
Источник: redhat
CVSS3: 5.9

Описание

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

A flaw was found in glibc. When the wordexp function is called with the flags WRDE_REUSE and WRDE_APPEND, it may return uninitialized memory. If the caller inspects the we_wordv array or calls the wordfree function to free the allocated memory, the process will abort, resulting in a denial of service.

Отчет

To exploit this issue, an attacker needs to find an application linked to the glibc library that is using the wordexp function with the flags WRDE_REUSE and WRDE_APPEND. Also, calls to wordexp using both flags never worked correctly and thus the existence of applications that make use of this feature is unlikely. There is no known application vulnerable to this issue. Furthermore, this flaw will result in a denial of service with no other security impact. Due to these reasons, this vulnerability has been rated with a low severity.

Меры по смягчению последствий

To mitigate this issue, consider refactoring the use of the wordexp function to not use the WRDE_REUSE and WRDE_APPEND flags together.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10glibcAffected
Red Hat Enterprise Linux 6compat-glibcFix deferred
Red Hat Enterprise Linux 6glibcFix deferred
Red Hat Enterprise Linux 7compat-glibcFix deferred
Red Hat Enterprise Linux 7glibcFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 8glibcFixedRHSA-2026:477217.03.2026
Red Hat Enterprise Linux 8glibcFixedRHSA-2026:477217.03.2026
Red Hat Enterprise Linux 9glibcFixedRHSA-2026:278617.02.2026
Red Hat Enterprise Linux 9glibcFixedRHSA-2026:278617.02.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-908
https://bugzilla.redhat.com/show_bug.cgi?id=2431196glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

CVSS3: 7.5
nvd
2 месяца назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

CVSS3: 6.2
msrc
2 месяца назад

wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

CVSS3: 7.5
debian
2 месяца назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the ...

CVSS3: 7.5
github
2 месяца назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

5.9 Medium

CVSS3