CVE-2025-15281: GNU Glibc

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

Affected products

  • GNU Glibc: from 2.0, before 2.43 (fixed in 2.43)

Published 2026-01-20. Last modified 2026-06-17.