{"id":"DEBIAN-CVE-2025-8058","details":"The regcomp function in the GNU C library version from 2.4 to 2.41 is  subject to a double free if some previous allocation fails. It can be  accomplished either by a malloc failure or by using an interposed malloc  that injects random malloc failures. The double free can allow buffer  manipulation depending of how the regex is constructed. This issue  affects all architectures and ABIs supported by the GNU C library.","modified":"2026-09-01T20:05:58.953216299Z","published":"2025-07-23T20:15:27.747Z","upstream":["CVE-2025-8058"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-8058"}],"affected":[{"package":{"name":"glibc","ecosystem":"Debian:12","purl":"pkg:deb/debian/glibc?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.36-9+deb12u13"}]}],"versions":["2.36-9","2.36-9+deb12u1","2.36-9+deb12u10","2.36-9+deb12u11","2.36-9+deb12u12","2.36-9+deb12u2","2.36-9+deb12u3","2.36-9+deb12u4","2.36-9+deb12u5","2.36-9+deb12u6","2.36-9+deb12u7","2.36-9+deb12u8","2.36-9+deb12u9"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-8058.json"}},{"package":{"name":"glibc","ecosystem":"Debian:13","purl":"pkg:deb/debian/glibc?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.41-11"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-8058.json"}},{"package":{"name":"glibc","ecosystem":"Debian:14","purl":"pkg:deb/debian/glibc?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.41-11"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-8058.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}