CVE-2025-5898: GNU Pspp
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to out-of-bounds write. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
Affected products
- GNU Pspp
Published 2025-06-09. Last modified 2026-06-17.