REDHAT-BUG-2431196: Low severity GNU C Library vulnerability
Published Jan 20, 2026
·Updated
Calling wordexp with WRDEREUSE in conjunction with WRDEAPPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the wewordv member, which on subsequent calls to wordfree may abort the process.
Affected Software
1 affected component
GNU C Library>=2.0<=2.42
Event History
Jan 20, 2026
Data Sourced
via Red Hat·02:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2431196?
REDHAT-BUG-2431196 has a high severity due to the potential for application crashes and memory corruption.
2
How do I fix REDHAT-BUG-2431196?
To fix REDHAT-BUG-2431196, update the GNU C Library to a version above 2.42.
3
What versions of the GNU C Library are affected by REDHAT-BUG-2431196?
REDHAT-BUG-2431196 affects GNU C Library versions from 2.0 to 2.42.
4
What impact does REDHAT-BUG-2431196 have on applications?
REDHAT-BUG-2431196 can lead to applications accessing uninitialized memory, resulting in crashes.
5
Is user data at risk due to REDHAT-BUG-2431196?
While REDHAT-BUG-2431196 primarily causes process aborts, it does not directly compromise user data.