CVE-2025-15281: GNU Glibc
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
Affected products
- GNU Glibc: from 2.0, before 2.43 (fixed in 2.43)
Published 2026-01-20. Last modified 2026-06-17.