HomeDefault status
unaffected
2.0 (custom)
affected
Description
Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
Problem types
CWE-908 Use of Uninitialized Resource
Product status
2.0 (custom)
Credits
Vitaly Simonovich
References
www.openwall.com/lists/oss-security/2026/01/20/3
sourceware.org/bugzilla/show_bug.cgi?id=33814