Uninitialized Memory Exposure in GNU C Library Versions 2.0 to 2.42
CVE-2025-15281

Currently unrated

Key Information:

Status
Vendor
CVE Published:
20 January 2026

What is CVE-2025-15281?

The GNU C Library versions 2.0 through 2.42 are susceptible to an uninitialized memory access vulnerability. This arises from the use of the wordexp function with both WRDE_REUSE and WRDE_APPEND flags. When invoked under these conditions, the we_wordv member may return uninitialized memory, leading to potential process terminations during subsequent calls to wordfree. Users should be aware of this issue and implement proper coding practices to avoid exploitation of this vulnerability.

Affected Version(s)

glibc 2.0 <= 2.42

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vitaly Simonovich
.