CVE-2025-15281 describes a vulnerability in the GNU C Library (glibc) versions 2.0 through 2.42, where improper use of wordexp with WRDE_REUSE and WRDE_APPEND can lead to the return of uninitialized memory, potentially causing a process abortion upon subsequent calls to wordfree. This is a high-severity vulnerability (CVSS 7.5) with a network attack vector and low attack complexity, allowing an unauthenticated attacker to achieve a denial of service. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion, indicating awareness and potential future interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0, < 2.43CPE matchmatch criteria | cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* | ||
>= 2.0, <= 2.42CPE match | cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.