Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Mageia 9 MGASA-2025-0026 critical: glibc buffer overflow

mageia
Calendar Grey January 26, 2025
Scroller Mageia
Mageia has released revised glibc packages addressing buffer overflow vulnerabilities within the assert() function as of January 26, 2025.
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which ...

Summary

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size. (CVE-2025-0395)

References

- https://bugs.mageia.org/show_bug.cgi?id=33953

- https://www.openwall.com/lists/oss-security/2025/01/22/4

- https://www.cve.org/CVERecord?id=CVE-2025-0395

Resolution

SRPMS

- 9/core/glibc-2.36-55.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 26 Jan 2025
URL: https://advisories.mageia.org/MGASA-2025-0026.html
Type: security
CVE: CVE-2025-0395

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.