CVE-2019-25013: Broadcom Fabric Operating System

Medium severity, CVSS 5.9. EPSS: 3.6% chance of exploitation in the next 30 days.

The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.

Affected products

  • Broadcom Fabric Operating System: affected versions not specified
  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 32 only; version 33 only
  • GNU Glibc: up to and including 2.32
  • Netapp 500f Firmware: affected versions not specified
  • Netapp a250 Firmware: affected versions not specified
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified
  • Netapp Service Processor: affected versions not specified

Published 2021-01-04. Last modified 2026-06-17.