CVE-2025-0395

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
Configurations

No configuration.

History

30 Apr 2025, 05:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/04/msg00039.html -

25 Apr 2025, 02:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/04/24/7 -

13 Apr 2025, 04:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/04/13/1 -

28 Feb 2025, 13:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250228-0006/ -

04 Feb 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

23 Jan 2025, 18:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/01/22/4 -
  • () http://www.openwall.com/lists/oss-security/2025/01/23/2 -
Summary
  • (es) Cuando la función assert() en las versiones GNU C Library 2.13 a 2.40 falla, no asigna suficiente espacio para la cadena de mensaje de error de aserción y la información de tamaño, lo que puede provocar un desbordamiento de búfer si el tamaño de la cadena del mensaje se alinea con el tamaño de la página.

22 Jan 2025, 16:15

Type Values Removed Values Added
References
  • () https://sourceware.org/pipermail/libc-announce/2025/000044.html -
  • () https://www.openwall.com/lists/oss-security/2025/01/22/4 -

22 Jan 2025, 15:15

Type Values Removed Values Added
References
  • () https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2025-0001 -

22 Jan 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-22 13:15

Updated : 2025-04-30 05:15


NVD link : CVE-2025-0395

Mitre link : CVE-2025-0395

CVE.ORG link : CVE-2025-0395


JSON object : View

Products Affected

No product.

CWE
CWE-131

Incorrect Calculation of Buffer Size