Integer overflow in abseil-cpp - CVE-2025-0838
Published: September 19, 2025
Vulnerability identifier: #VU115836
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-0838
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow. A remote attacker can pass a very large size that would cause an integer overflow when computing the size of the container's backing store, and a subsequent out-of-bounds memory write.
Affected software
abseil-cpp
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
abseil (Ubuntu package)
abseil-cpp-debugsource
abseil-cpp
abseil-cpp-debuginfo
abseil-cpp-devel
libabsl2308_0_0-64bit
libabsl2308_0_0-64bit-debuginfo
libabsl2308_0_0-32bit-debuginfo
libabsl2308_0_0-32bit
libabsl2308_0_0-debuginfo
libabsl2308_0_0
libabsl2401_0_0
libabsl2401_0_0-64bit-debuginfo
libabsl2401_0_0-64bit
libabsl2401_0_0-32bit
libabsl2401_0_0-32bit-debuginfo
libabsl2401_0_0-debuginfo
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
abseil (Ubuntu package)
abseil-cpp-debugsource
abseil-cpp
abseil-cpp-debuginfo
abseil-cpp-devel
libabsl2308_0_0-64bit
libabsl2308_0_0-64bit-debuginfo
libabsl2308_0_0-32bit-debuginfo
libabsl2308_0_0-32bit
libabsl2308_0_0-debuginfo
libabsl2308_0_0
libabsl2401_0_0
libabsl2401_0_0-64bit-debuginfo
libabsl2401_0_0-64bit
libabsl2401_0_0-32bit
libabsl2401_0_0-32bit-debuginfo
libabsl2401_0_0-debuginfo
How to mitigate CVE-2025-0838
Install updates from vendor's website.
abseil-cpp - update to 20250814 rc1
abseil (Ubuntu package) - addressed in versions 0~20210324.2-2ubuntu0.2, 20220623.1-3.1ubuntu3.2, 20230802.1-4ubuntu1.2, 20230802.1-4.2ubuntu0.2
abseil-cpp-debugsource - addressed in versions 20211102.0-150300.7.9.1, 20230802.3-150400.10.7.1, 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
abseil-cpp - update to 20211102.0-150300.7.9.1
abseil-cpp-debuginfo - update to 20211102.0-150300.7.9.1
abseil-cpp-devel - addressed in versions 20211102.0-150300.7.9.1, 20230802.3-150400.10.7.1, 20240116.3-8.6.1, 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
abseil-cpp-debuginfo - update to 20220623.1-6
abseil-cpp - update to 20220623.1-6
abseil-cpp-devel - update to 20220623.1-6
abseil-cpp-debugsource - update to 20220623.1-6
libabsl2308_0_0-64bit - update to 20230802.3-150400.10.7.1
libabsl2308_0_0-64bit-debuginfo - update to 20230802.3-150400.10.7.1
libabsl2308_0_0-32bit-debuginfo - update to 20230802.3-150400.10.7.1
libabsl2308_0_0-32bit - update to 20230802.3-150400.10.7.1
libabsl2308_0_0-debuginfo - update to 20230802.3-150400.10.7.1
libabsl2308_0_0 - update to 20230802.3-150400.10.7.1
libabsl2401_0_0 - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
libabsl2401_0_0-64bit-debuginfo - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
libabsl2401_0_0-64bit - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
libabsl2401_0_0-32bit - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
libabsl2401_0_0-32bit-debuginfo - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
libabsl2401_0_0-debuginfo - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
abseil (Ubuntu package) - addressed in versions 0~20210324.2-2ubuntu0.2, 20220623.1-3.1ubuntu3.2, 20230802.1-4ubuntu1.2, 20230802.1-4.2ubuntu0.2
abseil-cpp-debugsource - addressed in versions 20211102.0-150300.7.9.1, 20230802.3-150400.10.7.1, 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
abseil-cpp - update to 20211102.0-150300.7.9.1
abseil-cpp-debuginfo - update to 20211102.0-150300.7.9.1
abseil-cpp-devel - addressed in versions 20211102.0-150300.7.9.1, 20230802.3-150400.10.7.1, 20240116.3-8.6.1, 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
abseil-cpp-debuginfo - update to 20220623.1-6
abseil-cpp - update to 20220623.1-6
abseil-cpp-devel - update to 20220623.1-6
abseil-cpp-debugsource - update to 20220623.1-6
libabsl2308_0_0-64bit - update to 20230802.3-150400.10.7.1
libabsl2308_0_0-64bit-debuginfo - update to 20230802.3-150400.10.7.1
libabsl2308_0_0-32bit-debuginfo - update to 20230802.3-150400.10.7.1
libabsl2308_0_0-32bit - update to 20230802.3-150400.10.7.1
libabsl2308_0_0-debuginfo - update to 20230802.3-150400.10.7.1
libabsl2308_0_0 - update to 20230802.3-150400.10.7.1
libabsl2401_0_0 - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
libabsl2401_0_0-64bit-debuginfo - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
libabsl2401_0_0-64bit - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
libabsl2401_0_0-32bit - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
libabsl2401_0_0-32bit-debuginfo - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
libabsl2401_0_0-debuginfo - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1