Integer overflow in abseil-cpp - CVE-2025-0838

 

Integer overflow in abseil-cpp - CVE-2025-0838

Published: September 19, 2025


Vulnerability identifier: #VU115836
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-0838
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow. A remote attacker can pass a very large size that would cause an integer overflow when computing the size of the container's backing store, and a subsequent out-of-bounds memory write.


Affected software

abseil-cpp
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
abseil (Ubuntu package)
abseil-cpp-debugsource
abseil-cpp
abseil-cpp-debuginfo
abseil-cpp-devel
libabsl2308_0_0-64bit
libabsl2308_0_0-64bit-debuginfo
libabsl2308_0_0-32bit-debuginfo
libabsl2308_0_0-32bit
libabsl2308_0_0-debuginfo
libabsl2308_0_0
libabsl2401_0_0
libabsl2401_0_0-64bit-debuginfo
libabsl2401_0_0-64bit
libabsl2401_0_0-32bit
libabsl2401_0_0-32bit-debuginfo
libabsl2401_0_0-debuginfo

How to mitigate CVE-2025-0838

Install updates from vendor's website.

abseil-cpp - update to 20250814 rc1
abseil (Ubuntu package) - addressed in versions 0~20210324.2-2ubuntu0.2, 20220623.1-3.1ubuntu3.2, 20230802.1-4ubuntu1.2, 20230802.1-4.2ubuntu0.2
abseil-cpp-debugsource - addressed in versions 20211102.0-150300.7.9.1, 20230802.3-150400.10.7.1, 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
abseil-cpp - update to 20211102.0-150300.7.9.1
abseil-cpp-debuginfo - update to 20211102.0-150300.7.9.1
abseil-cpp-devel - addressed in versions 20211102.0-150300.7.9.1, 20230802.3-150400.10.7.1, 20240116.3-8.6.1, 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
abseil-cpp-debuginfo - update to 20220623.1-6
abseil-cpp - update to 20220623.1-6
abseil-cpp-devel - update to 20220623.1-6
abseil-cpp-debugsource - update to 20220623.1-6
libabsl2308_0_0-64bit - update to 20230802.3-150400.10.7.1
libabsl2308_0_0-64bit-debuginfo - update to 20230802.3-150400.10.7.1
libabsl2308_0_0-32bit-debuginfo - update to 20230802.3-150400.10.7.1
libabsl2308_0_0-32bit - update to 20230802.3-150400.10.7.1
libabsl2308_0_0-debuginfo - update to 20230802.3-150400.10.7.1
libabsl2308_0_0 - update to 20230802.3-150400.10.7.1
libabsl2401_0_0 - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
libabsl2401_0_0-64bit-debuginfo - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
libabsl2401_0_0-64bit - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
libabsl2401_0_0-32bit - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
libabsl2401_0_0-32bit-debuginfo - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1
libabsl2401_0_0-debuginfo - addressed in versions 20240116.3-150500.13.10.1, 20240116.3-150600.19.6.1

External References

Related Security Bulletins