Uninitialized Memory Exposure in GNU C Library Versions 2.0 to 2.42
CVE-2025-15281

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
20 January 2026

What is CVE-2025-15281?

The GNU C Library versions 2.0 through 2.42 are susceptible to an uninitialized memory access vulnerability. This arises from the use of the wordexp function with both WRDE_REUSE and WRDE_APPEND flags. When invoked under these conditions, the we_wordv member may return uninitialized memory, leading to potential process terminations during subsequent calls to wordfree. Users should be aware of this issue and implement proper coding practices to avoid exploitation of this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

glibc 2.0 <= 2.42

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vitaly Simonovich
.