CVE-2025-0395

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
Configurations

No configuration.

History

25 Apr 2025, 02:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/04/24/7 -

13 Apr 2025, 04:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/04/13/1 -

28 Feb 2025, 13:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250228-0006/ -

04 Feb 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

23 Jan 2025, 18:15

Type Values Removed Values Added
Summary
  • (es) Cuando la función assert() en las versiones GNU C Library 2.13 a 2.40 falla, no asigna suficiente espacio para la cadena de mensaje de error de aserción y la información de tamaño, lo que puede provocar un desbordamiento de búfer si el tamaño de la cadena del mensaje se alinea con el tamaño de la página.
References
  • () http://www.openwall.com/lists/oss-security/2025/01/22/4 -
  • () http://www.openwall.com/lists/oss-security/2025/01/23/2 -

22 Jan 2025, 16:15

Type Values Removed Values Added
References
  • () https://sourceware.org/pipermail/libc-announce/2025/000044.html -
  • () https://www.openwall.com/lists/oss-security/2025/01/22/4 -

22 Jan 2025, 15:15

Type Values Removed Values Added
References
  • () https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2025-0001 -

22 Jan 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-22 13:15

Updated : 2025-04-25 02:15


NVD link : CVE-2025-0395

Mitre link : CVE-2025-0395

CVE.ORG link : CVE-2025-0395


JSON object : View

Products Affected

No product.

CWE
CWE-131

Incorrect Calculation of Buffer Size