CVE Database
/

CVE-2025-15281

Back to search

CVE-2025-15281

Published: Jan 20, 2026

Modified: Jan 22, 2026

PUBLISHED

Description

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

VendorProductVersions

The GNU C Library

glibc

affected
2.0 - <= 2.42

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now