RHSA-2026:18139MediumCVSS 5.9
Red Hat Security Advisory: glibc security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2025-15281 — glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory
🎯 Affected products200
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux BaseOS (v. 10)
- Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- glibc-0:2.39-113.el10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- glibc-0:2.39-113.el10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- glibc-0:2.39-113.el10.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- glibc-0:2.39-113.el10.src as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- glibc-0:2.39-113.el10.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- glibc-all-langpacks-0:2.39-113.el10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- glibc-all-langpacks-0:2.39-113.el10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- glibc-all-langpacks-0:2.39-113.el10.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- glibc-all-langpacks-0:2.39-113.el10.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- glibc-benchtests-0:2.39-113.el10.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- glibc-benchtests-0:2.39-113.el10.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- glibc-benchtests-0:2.39-113.el10.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- glibc-benchtests-0:2.39-113.el10.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- glibc-benchtests-debuginfo-0:2.39-113.el10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- glibc-benchtests-debuginfo-0:2.39-113.el10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- glibc-benchtests-debuginfo-0:2.39-113.el10.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- glibc-benchtests-debuginfo-0:2.39-113.el10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- glibc-benchtests-debuginfo-0:2.39-113.el10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- glibc-benchtests-debuginfo-0:2.39-113.el10.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- glibc-benchtests-debuginfo-0:2.39-113.el10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- glibc-benchtests-debuginfo-0:2.39-113.el10.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- glibc-benchtests-debuginfo-0:2.39-113.el10.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- glibc-benchtests-debuginfo-0:2.39-113.el10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- glibc-benchtests-debuginfo-0:2.39-113.el10.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- glibc-benchtests-debuginfo-0:2.39-113.el10.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
- glibc-common-0:2.39-113.el10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- glibc-common-0:2.39-113.el10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, consider refactoring the use of the wordexp function to not use the WRDE_REUSE and WRDE_APPEND flags together.
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2026:18139
- externalhttps://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/html/10.2_release_notes/index
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2431196
- externalhttps://issues.redhat.com/browse/RHEL-102553
- externalhttps://issues.redhat.com/browse/RHEL-111490
- externalhttps://issues.redhat.com/browse/RHEL-113195
- externalhttps://issues.redhat.com/browse/RHEL-116641
- externalhttps://issues.redhat.com/browse/RHEL-126046
- externalhttps://issues.redhat.com/browse/RHEL-126049
- externalhttps://issues.redhat.com/browse/RHEL-126766
- externalhttps://issues.redhat.com/browse/RHEL-127524
- externalhttps://issues.redhat.com/browse/RHEL-137184
- externalhttps://issues.redhat.com/browse/RHEL-140103
- externalhttps://issues.redhat.com/browse/RHEL-65838
- externalhttps://issues.redhat.com/browse/RHEL-72244
- externalhttps://issues.redhat.com/browse/RHEL-87645
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_18139.json