Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-15281

Опубликовано: 20 янв. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

needed

jammy

DNE

noble

DNE

questing

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

pending

2.42-2ubuntu5
esm-infra/bionic

released

2.27-3ubuntu1.6+esm6
esm-infra/focal

released

2.31-0ubuntu9.18+esm1
esm-infra/xenial

released

2.23-0ubuntu11.3+esm9
jammy

released

2.35-0ubuntu3.13
noble

released

2.39-0ubuntu8.7
questing

released

2.42-0ubuntu3.1
upstream

released

2.42-11

Показывать по

EPSS

Процентиль: 16%
0.00052
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
18 дней назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

CVSS3: 7.5
debian
18 дней назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the ...

CVSS3: 7.5
github
18 дней назад

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

suse-cvrf
4 дня назад

Security update for glibc

suse-cvrf
9 дней назад

Security update for glibc

EPSS

Процентиль: 16%
0.00052
Низкий

7.5 High

CVSS3