CVE-2025-15281

NameCVE-2025-15281
DescriptionCalling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1126266

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
glibc (PTS)bullseye2.31-13+deb11u11vulnerable
bullseye (security)2.31-13+deb11u13vulnerable
bookworm2.36-9+deb12u13vulnerable
bookworm (security)2.36-9+deb12u7vulnerable
trixie2.41-12+deb13u1vulnerable
forky2.42-11fixed
sid2.42-12fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
glibcsource(unstable)2.42-111126266

Notes

[trixie] - glibc <no-dsa> (Minor issue)
[bookworm] - glibc <no-dsa> (Minor issue)
[bullseye] - glibc <postponed> (Minor issue, unlikely scenario)
https://www.openwall.com/lists/oss-security/2026/01/20/3
Introduced with: https://sourceware.org/git/?p=glibc.git;a=commit;h=8f2ece695d8822e9ecc63ecd157e90bf17a6fe65 (glibc-2.0.92)
Fixed by: https://sourceware.org/git/?p=glibc.git;a=commit;h=80cc58ea2de214f85b0a1d902a3b668ad2ecb302 (glibc-2.43)

Search for package or bug name: Reporting problems