Alerts This Week
Warning Icon 1 460
Alerts This Week
Warning Icon 1 460

Debian LTS glibc Critical Memory Management Issues DLA-4621-1 CVE-2025-8058

debian lts
Calendar Grey June 8, 2026
Dist Debian Esm H88
Various vulnerabilities in glibc affect Debian users; it's critical to update to the patched version for security.
Several vulnerabilities have been discovered in the GNU C Library, the C standard library implementation used by Debian

Summary

CVE-2025-8058

posix: Fix double-free after allocation failure in regcomp

The regcomp function in the GNU C library version from 2.4 to 2.41 is
subject to a double free if some previous allocation fails. It can be
accomplished either by a malloc failure or by using an interposed
malloc that injects random malloc failures. The double free can allow
buffer manipulation depending of how the regex is constructed. This
issue affects all architectures and ABIs supported by the GNU C
library.

CVE-2025-15281

posix: Reset wordexp_t fields with WRDE_REUSE

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the
GNU C Library version 2.0 to version 2.42 may cause the interface to
return uninitialized memory in the we_wordv member, which on
subsequent calls to wordfree may abort the process.

CVE-2026-0861

memalign: reinstate alignment overflow check

Passing too large an alignment to the memalign suite of functions

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: glibc
Version: 2.31-13+deb11u14
CVE ID: CVE-2025-8058 CVE-2025-15281 CVE-2026-0861 CVE-2026-0915
Debian Bug: 1109803 1125678 1125748 1126266 1132499

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here