Uninitialized Memory Exposure in GNU C Library Versions 2.0 to 2.42
CVE-2025-15281
Currently unrated
What is CVE-2025-15281?
The GNU C Library versions 2.0 through 2.42 are susceptible to an uninitialized memory access vulnerability. This arises from the use of the wordexp function with both WRDE_REUSE and WRDE_APPEND flags. When invoked under these conditions, the we_wordv member may return uninitialized memory, leading to potential process terminations during subsequent calls to wordfree. Users should be aware of this issue and implement proper coding practices to avoid exploitation of this vulnerability.
Affected Version(s)
glibc 2.0 <= 2.42
