#VU122300 Use of uninitialized resource in GNU C Library (glibc) - CVE-2025-15281
Published: February 4, 2026
GNU C Library (glibc)
GNU
Description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to usage of uninitialized resources when calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND. A remote attacker can pass specially crafted data to the application, trigger an uninitialized usage of resources and crash the application.