RHSA-2026:18139MediumCVSS 5.9

Red Hat Security Advisory: glibc security update

Published
May 19, 2026
Last Modified
August 17, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-15281 — glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory

🎯 Affected products200

  • Red Hat Enterprise Linux AppStream (v. 10)
  • Red Hat Enterprise Linux BaseOS (v. 10)
  • Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • glibc-0:2.39-113.el10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • glibc-0:2.39-113.el10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • glibc-0:2.39-113.el10.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • glibc-0:2.39-113.el10.src as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • glibc-0:2.39-113.el10.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • glibc-all-langpacks-0:2.39-113.el10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • glibc-all-langpacks-0:2.39-113.el10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • glibc-all-langpacks-0:2.39-113.el10.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • glibc-all-langpacks-0:2.39-113.el10.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • glibc-benchtests-0:2.39-113.el10.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • glibc-benchtests-0:2.39-113.el10.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • glibc-benchtests-0:2.39-113.el10.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • glibc-benchtests-0:2.39-113.el10.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • glibc-benchtests-debuginfo-0:2.39-113.el10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • glibc-benchtests-debuginfo-0:2.39-113.el10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • glibc-benchtests-debuginfo-0:2.39-113.el10.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • glibc-benchtests-debuginfo-0:2.39-113.el10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • glibc-benchtests-debuginfo-0:2.39-113.el10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • glibc-benchtests-debuginfo-0:2.39-113.el10.ppc64le as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • glibc-benchtests-debuginfo-0:2.39-113.el10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • glibc-benchtests-debuginfo-0:2.39-113.el10.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • glibc-benchtests-debuginfo-0:2.39-113.el10.s390x as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • glibc-benchtests-debuginfo-0:2.39-113.el10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • glibc-benchtests-debuginfo-0:2.39-113.el10.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • glibc-benchtests-debuginfo-0:2.39-113.el10.x86_64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 10)
  • glibc-common-0:2.39-113.el10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • glibc-common-0:2.39-113.el10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, consider refactoring the use of the wordexp function to not use the WRDE_REUSE and WRDE_APPEND flags together.

🔗 References (18)