Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-8058

16
FAUCET Score

CVE-2025-8058 describes a double free vulnerability in the regcomp function of the GNU C library, affecting versions 2.4 through 2.41. This flaw can be triggered by memory allocation failures, potentially leading to buffer manipulation depending on the regex construction. With a CVSSv4 score of 5.9 (MEDIUM), exploitation requires local access and user interaction, but could result in high availability impact. Currently, there is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.4, < 2.42CPE match
cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.9MEDIUM

CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
PASSIVE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
HIGH
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 54th percentile among its peer group of 296 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (26)

microsoftpatch availablevia msrc
Product: azl3 glibc 2.38-14 on Azure Linux 3.0Fixed in: 2.38-15
microsoftpatch availablevia msrc
Product: azl3 glibc 2.38-15 on Azure Linux 3.0Fixed in: 2.38-15
microsoftpatch availablevia msrc
Product: 20570-17084Fixed in: 2.38-15
microsoftpatch availablevia msrc
Product: 20614-17084Fixed in: 2.38-15
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-server-rhel9:sha256:7d200c5dcd40e0885171fe20e3edb5d432a8675080846fb3ba273c601c5957a1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Insights proxy 1.5Fixed in: insights-proxy/insights-proxy-container-rhel9:sha256:e54a5a5f9d69dd6a03e2bcd845e2202910a188d266d4a79b12c387ceffc36f2d
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.5.1Fixed in: rhosdt/jaeger-agent-rhel8:sha256:6f387ea61bf4d0c11c8fadd8225d2eca24d19e28d596afa800149925154a345a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.5.1Fixed in: rhosdt/jaeger-all-in-one-rhel8:sha256:1ed7ca9ba1fe229bb04b4b59b0a7161286786c025d5dbe688d3e68e0af85945b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.5.1Fixed in: rhosdt/jaeger-collector-rhel8:sha256:593c9e2656e624b444bd45740c6e556c06137ab6cf7aaa0387799b10669b74e9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.5.1Fixed in: rhosdt/jaeger-es-index-cleaner-rhel8:sha256:c56438a8b89d2c25209e3b50a6d45e050c26b514179d0781e7ee223f32dce7d2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.5.1Fixed in: rhosdt/jaeger-es-rollover-rhel8:sha256:a49b8de5c60cd6af7fd0d70fbf0c7e9ae0b4e26eebe2ed2b4490e756ff07fa9c
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.5.1Fixed in: rhosdt/jaeger-ingester-rhel8:sha256:b8ab8265ceed867796cf63e05b3c2b161ef289ec0ff1337c4b5c763228e747f3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.5.1Fixed in: rhosdt/jaeger-operator-bundle:sha256:264613b2add0f32e5f537ee7cf9ba8019e5e9a347fdf20bc3de8d1678157ba66
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: glibc-0:2.39-46.el10_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.5.1Fixed in: rhosdt/jaeger-rhel8-operator:sha256:ef79fd809a6406f43bc90dc685ca2819694096abe4c4de7f6302a09683f883fd
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.5.1Fixed in: rhosdt/jaeger-query-rhel8:sha256:86d7a8aed1a64c10b5a52f56966645ed62ee40cd38c034bfe00b87ee4e3558a4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: glibc-0:2.28-251.el8_10.25
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: glibc-0:2.34-168.el9_6.23
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 7Fixed in: rhceph/rhceph-7-rhel9:sha256:ce213d48fbefae6b9d5f5a64b79c6ed016afcb646bf7b5742707ed31f9a464a2
View patch
grafanavendor investigatingvia llm_extracted
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: compat-glibc
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: glibc
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: glibc
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: compat-glibc
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: nss_db

Vendor Advisories (3)

grafanallm-grafana-3bfe68bd8f94bc6dCRITICAL

HP ThinPro 8.1 SP9 Security Updates

Feb 2, 2026
redhatCVE-2025-8058Moderate

glibc: Double free in glibc

Jul 23, 2025
microsoft2025-Jul/CVE-2025-8058Moderate

The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc that injects random malloc failures. The double free can allow buffer manipulation depending of how the regex is constructed. This issue affects all architectures and ABIs supported by the GNU C library.

Jul 8, 2025

References

sourceware.org / bugzilla/show_bug.cgi
sourceware.org / git
openwall.com / lists/oss-security/2025/07/23/1