CVE Explorer
CVE-2025-8058
The regcomp function in the GNU C library version from 2.4 to 2.41 is
subject to a double free if some previous allocation fails. It can be
accomplished either by a malloc failure or by using an interposed malloc
that injects random malloc failures. The double free can allow buffer
manipulation depending of how the regex is constructed. This issue
affects all architectures and ABIs supported by the GNU C library.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://www.gnu.org/software/libc/","defaultStatus":"unaffected","packageName":"glibc","platforms":["Linux"],"product":"glibc","repo":"https://sourceware.org/git/?p=glibc.git","vendor":"The GNU C Library","versions":[{"lessThan":"2.42","status":"affected","version":"2.4","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:1c07e6c4a4211864f20458c2de4956a3342245dd8b64c969090b9057ac060f4c · sha256:c78a0915ac60a459… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"PRESENT","attackVector":"LOCAL","baseScore":5.9,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"PASSIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:1c07e6c4a4211864f20458c2de4956a3342245dd8b64c969090b9057ac060f4c · sha256:c78a0915ac60a459… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-415","description":"CWE-415 Double Free","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1c07e6c4a4211864f20458c2de4956a3342245dd8b64c969090b9057ac060f4c · sha256:c78a0915ac60a459… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"url":"http://www.openwall.com/lists/oss-security/2025/07/23/1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1c07e6c4a4211864f20458c2de4956a3342245dd8b64c969090b9057ac060f4c · sha256:c78a0915ac60a459… · /containers/adp/1/references/0
{"url":"https://sourceware.org/bugzilla/show_bug.cgi?id=33185"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1c07e6c4a4211864f20458c2de4956a3342245dd8b64c969090b9057ac060f4c · sha256:c78a0915ac60a459… · /containers/cna/references/0
{"url":"https://sourceware.org/git/?p=glibc.git;a=commit;h=3ff17af18c38727b88d9115e536c069e6b5d601f"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1c07e6c4a4211864f20458c2de4956a3342245dd8b64c969090b9057ac060f4c · sha256:c78a0915ac60a459… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.