CVE-2025-0395
published 2025-01-22CVE-2025-0395: When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and…
PriorityP423medium6.2CVSS 3.1
AVLACLPRNUINSUCNINAH
EPSS
0.35%
27.2th percentile
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.36-9+deb12u10 (bookworm) | glibc 2.36-9+deb12u10 (bookworm) |
| gnu | glibc | >= 0 < 2.31-13+deb11u12 | 2.31-13+deb11u12 |
| gnu | glibc | >= 0 < 2.36-9+deb12u10 | 2.36-9+deb12u10 |
| gnu | glibc | >= 0 < 2.40-6 | 2.40-6 |
| gnu | glibc | >= 0 < 2.40-6 | 2.40-6 |
| the_gnu_c_library | glibc | 2.13 – 2.40 | — |
CVSS provenance
nvdv3.16.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
vendor_oracle5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Signaling (glibc) — CVE-2025-0395
vendor_oracle·2025-07-15·CVSS 5.5
CVE-2025-0395 [MEDIUM] Oracle Oracle Communications Risk Matrix: Signaling (glibc) — CVE-2025-0395
Oracle Oracle Communications Risk Matrix: Signaling (glibc) vulnerability
CVE: CVE-2025-0395
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2025 (JUL 2025)
Ubuntu
GNU C Library vulnerability
vendor_ubuntu·2025-02-10
CVE-2025-0395 GNU C Library vulnerability
Title: GNU C Library vulnerability
Summary: GNU C Library could be made to crash or run programs if it received
specially crafted input.
USN-7259-1 fixed a vulnerability in GNU C Library. This update provides the
corresponding update for Ubuntu 16.04 LTS.
Original advisory details:
It was discovered that GNU C Library incorrectly handled memory when using
the assert function. An attacker could possibly use this issue to cause a
denial of service or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GNU C Library vulnerability
vendor_ubuntu·2025-02-10
CVE-2025-0395 GNU C Library vulnerability
Title: GNU C Library vulnerability
Summary: GNU C Library could be made to crash or run programs if it received
specially crafted input.
USN-7259-1 fixed a vulnerability in GNU C Library. This update provides the
corresponding update for Ubuntu 14.04 LTS.
Original advisory details:
It was discovered that GNU C Library incorrectly handled memory when using
the assert function. An attacker could possibly use this issue to cause a
denial of service or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GNU C Library vulnerability
vendor_ubuntu·2025-02-06
CVE-2025-0395 GNU C Library vulnerability
Title: GNU C Library vulnerability
Summary: GNU C Library could be made to crash or run programs if it received
specially crafted input.
It was discovered that GNU C Library incorrectly handled memory when using
the assert function. An attacker could possibly use this issue to cause a
denial of service or execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
glibc: buffer overflow in the GNU C Library's assert()
vendor_redhat·2025-01-22·CVSS 6.2
CVE-2025-0395 [MEDIUM] CWE-131 glibc: buffer overflow in the GNU C Library's assert()
glibc: buffer overflow in the GNU C Library's assert()
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
A flaw was found in the GNU C Library (glibc). A buffer overflow condition via the `assert()` function may be triggered due to glibc not allocating enough space for the assertion failure message string and size information. In certain conditions, a local attacker can exploit this, potentially leading to an application crash or other undefined behavior.
Statement: The bug is with glib assert() function that is typically used to identify logic errors in programs. The specific vulne
Debian
CVE-2025-0395: glibc - When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it ...
vendor_debian·2025·CVSS 6.2
CVE-2025-0395 [MEDIUM] CVE-2025-0395: glibc - When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it ...
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
Scope: local
bookworm: resolved (fixed in 2.36-9+deb12u10)
bullseye: resolved (fixed in 2.31-13+deb11u12)
forky: resolved (fixed in 2.40-6)
sid: resolved (fixed in 2.40-6)
trixie: resolved (fixed in 2.40-6)
OSV
CVE-2025-0395: When the assert() function in the GNU C Library versions 2
osv·2025-01-22·CVSS 6.2
CVE-2025-0395 [MEDIUM] CVE-2025-0395: When the assert() function in the GNU C Library versions 2
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
GHSA
GHSA-4xpw-6594-8f5m: When the assert() function in the GNU C Library versions 2
ghsa_unreviewed·2025-01-22
CVE-2025-0395 [HIGH] CWE-131 GHSA-4xpw-6594-8f5m: When the assert() function in the GNU C Library versions 2
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://sourceware.org/bugzilla/show_bug.cgi?id=32582https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2025-0001https://sourceware.org/pipermail/libc-announce/2025/000044.htmlhttps://www.openwall.com/lists/oss-security/2025/01/22/4http://www.openwall.com/lists/oss-security/2025/01/22/4http://www.openwall.com/lists/oss-security/2025/01/23/2http://www.openwall.com/lists/oss-security/2025/04/13/1http://www.openwall.com/lists/oss-security/2025/04/24/7https://lists.debian.org/debian-lts-announce/2025/04/msg00039.htmlhttps://security.netapp.com/advisory/ntap-20250228-0006/https://cert-portal.siemens.com/productcert/html/ssa-398330.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-577017.html
2025-01-22
Published