CVE-2025-0395

Siemens ProductCERT Advisory SSA-398330

mediumEPSS 0.4%

Description

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.

Metrics

Severity
medium
no public PoC known
6.2
Source: nvd-v3
28.8 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2022-03-15 17:05 UTC
CWE-131

Weakness classes (CWE)

  • CWE-131Base

    Incorrect Calculation of Buffer Size

    The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.

    cwe.mitre.org →

Affected operating systems

  • linux

    debian / debian_linux10.0

  • linux

    debian / debian_linux11.0

  • linux

    debian / debian_linux9.0

  • linux

    ubuntu / linuxbionic

  • linux

    ubuntu / linux-awsbionic

  • linux

    ubuntu / linux-aws-fipsbionic

  • linux

    ubuntu / linux-azure-4.15bionic

  • linux

    ubuntu / linux-azure-fipsbionic

  • linux

    ubuntu / linux-fipsbionic

  • linux

    ubuntu / linux-gcp-4.15bionic

  • linux

    ubuntu / linux-gcp-fipsbionic

  • linux

    ubuntu / linux-kvmbionic

  • linux

    linux / linux_kernel6.10

  • linux

    linux / linux_kernel6.11

  • linux

    linux / linux_kernel6.12

  • linux

    linux / linux_kernel6.13

  • linux

    linux / linux_kernel6.9

  • linux

    linux / linux_kernel

  • linux

    ubuntu / opensslbionic

  • linux

    ubuntu / opensslfocal

  • linux

    ubuntu / openssltrusty

  • linux

    ubuntu / opensslxenial

  • linux

    ubuntu / openssl1.0bionic

  • macos

    apple / mac_os_x10.15.7

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • android

    :linux_kernel::0

  • android

    :linux_kernel:Kernel

  • azul

    zulu

  • bitnami

    node-min12.0.0

  • bitnami

    node-min12.13.0

  • bitnami

    node-min14.0.0

  • bitnami

    node-min14.15.0

  • bitnami

    node-min16.0.0

  • bitnami

    node-min16.13.0

  • bitnami

    node-min17.0.0

  • Dell

    NetWorkerVirtual Edition

  • Dell

    NetWorkervProxy

  • Dell

    PowerProtect Data Domain7.10.1.70

  • Dell

    PowerProtect Data Domain7.13.1.40

  • Dell

    PowerProtect Data Domain8.3.1.10

  • Dell

    PowerProtect Data Domain8.4.0.0

  • Dell

    PowerProtect Data Domain< 7.10.1.70

    fixed in 7.10.1.70

  • Dell

    PowerProtect Data Domain< 7.13.1.40

    fixed in 7.13.1.40

  • Dell

    PowerProtect Data Domain< 8.3.1.10

    fixed in 8.3.1.10

  • Dell

    PowerProtect Data Domain< 8.4.0.0

    fixed in 8.4.0.0

  • goto

    gotoassist11.9.18

  • HPE

    HP-UXOpenSSL Software <A.03.00.15.001

  • IBM

    AIX7.2

  • IBM

    AIX7.3

References & sources

Linked CVEs

Show 37 more CVEs
IDCVE-2025-0395