CVE-2025-15281
published 2026-01-20CVE-2025-15281: Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.44%
35.7th percentile
Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.42-11 (forky) | glibc 2.42-11 (forky) |
| gnu | glibc | >= 0 < 2.41-12+deb13u2 | 2.41-12+deb13u2 |
| gnu | glibc | >= 0 < 2.42-11 | 2.42-11 |
| gnu | glibc | >= 0 < 2.35-0ubuntu3.13 | 2.35-0ubuntu3.13 |
| gnu | glibc | >= 0 < 2.39-0ubuntu8.7 | 2.39-0ubuntu8.7 |
| gnu | glibc | >= 0 < 2.42-0ubuntu3.1 | 2.42-0ubuntu3.1 |
| gnu | glibc | >= 0 < 2.23-0ubuntu11.3+esm9 | 2.23-0ubuntu11.3+esm9 |
| gnu | glibc | >= 0 < 2.27-3ubuntu1.6+esm6 | 2.27-3ubuntu1.6+esm6 |
| gnu | glibc | >= 0 < 2.31-0ubuntu9.18+esm1 | 2.31-0ubuntu9.18+esm1 |
| gnu | glibc | >= 2.0 < 2.43 | 2.43 |
| the_gnu_c_library | glibc | 2.0 – 2.42 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2026-02-03·CVSS 7.5
CVE-2026-0861 [HIGH] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
Vitaly Simonovich discovered that the GNU C Library did not properly
initialize the input when WRDE_REUSE is used. An attacker could possibly
use this issue to cause applications to crash, leading to a denial of
service. (CVE-2025-15281)
Anastasia Belova discovered that the GNU C Library incorrectly handled
the regcomp function when memory allocation failures occured. An attacker
could possibly use this issue to cause applications to crash, leading to
a denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2025-8058)
Igor Morgenstern discovered that the GNU C Library incorrectly handled
the memalign fu
Red Hat
glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory
vendor_redhat·2026-01-20·CVSS 7.5
CVE-2025-15281 [HIGH] CWE-908 glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory
glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory
Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
A flaw was found in glibc. When the wordexp function is called with the flags WRDE_REUSE and WRDE_APPEND, it may return uninitialized memory. If the caller inspects the we_wordv array or calls the wordfree function to free the allocated memory, the process will abort, resulting in a denial of service.
Statement: To exploit this issue, an attacker needs to find an application linked to the glibc library that is using the wordexp function with the flags WRDE_REUS
Debian
CVE-2025-15281: glibc - Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Lib...
vendor_debian·2025·CVSS 7.5
CVE-2025-15281 [HIGH] CVE-2025-15281: glibc - Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Lib...
Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.42-11)
sid: resolved (fixed in 2.42-11)
trixie: resolved (fixed in 2.41-12+deb13u2)
OSV
glibc vulnerabilities
osv·2026-02-03·CVSS 7.5
CVE-2025-15281 [HIGH] glibc vulnerabilities
glibc vulnerabilities
Vitaly Simonovich discovered that the GNU C Library did not properly
initialize the input when WRDE_REUSE is used. An attacker could possibly
use this issue to cause applications to crash, leading to a denial of
service. (CVE-2025-15281)
Anastasia Belova discovered that the GNU C Library incorrectly handled
the regcomp function when memory allocation failures occured. An attacker
could possibly use this issue to cause applications to crash, leading to
a denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2025-8058)
Igor Morgenstern discovered that the GNU C Library incorrectly handled
the memalign function when doing memory allocation. An attacker could
possibly use this issue
GHSA
GHSA-qg56-4cfq-w9w3: Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2
ghsa_unreviewed·2026-01-20
CVE-2025-15281 [HIGH] CWE-908 GHSA-qg56-4cfq-w9w3: Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2
Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
OSV
CVE-2025-15281: Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2
osv·2026-01-20·CVSS 7.5
CVE-2025-15281 [HIGH] CVE-2025-15281: Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2
Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-15281 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-15281 [HIGH] CVE-2025-15281 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-15281 :
NixOS vulnerability analysis and mitigation
Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
Source : NVD
## 7.5
Score
Published January 20, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
NixOS
Rocky Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 21.2
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
glibc-langpack-az
glibc-static
Sources
NVD
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Mar 20, 2026
AlmaLinux 9 Severity MED
Bugzilla
CVE-2025-15281 glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory
bugzilla·2026-01-20·CVSS 7.5
CVE-2025-15281 [HIGH] CVE-2025-15281 glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory
CVE-2025-15281 glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory
Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:2786 https://access.redhat.com/errata/RHSA-2026:2786
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2026:4772 https://access.redhat.com/errata/RHSA-2026:4772
2026-01-20
Published