{
  "threat_severity" : "Moderate",
  "public_date" : "2025-07-23T19:57:17Z",
  "bugzilla" : {
    "description" : "glibc: Double free in glibc",
    "id" : "2383146",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2383146"
  },
  "cvss3" : {
    "cvss3_base_score" : "4.2",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-415",
  "details" : [ "The regcomp function in the GNU C library version from 2.4 to 2.41 is \nsubject to a double free if some previous allocation fails. It can be \naccomplished either by a malloc failure or by using an interposed malloc\nthat injects random malloc failures. The double free can allow buffer \nmanipulation depending of how the regex is constructed. This issue \naffects all architectures and ABIs supported by the GNU C library.", "A double-free vulnerability has been discovered in glibc (GNU C Library). This flaw occurs during bracket expression parsing within the regcomp function, specifically when a memory allocation failure takes place. Exploitation of a double-free vulnerability can lead to memory corruption, which could enable an attacker to achieve arbitrary code execution or a denial of service condition." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2025-08-06T00:00:00Z",
    "advisory" : "RHSA-2025:13240",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.0",
    "package" : "glibc-0:2.39-46.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2025-08-05T00:00:00Z",
    "advisory" : "RHSA-2025:12980",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "glibc-0:2.28-251.el8_10.25"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2025-08-05T00:00:00Z",
    "advisory" : "RHSA-2025:12980",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8",
    "package" : "glibc-0:2.28-251.el8_10.25"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2025-08-04T00:00:00Z",
    "advisory" : "RHSA-2025:12748",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "glibc-0:2.34-168.el9_6.23"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2025-08-04T00:00:00Z",
    "advisory" : "RHSA-2025:12748",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "glibc-0:2.34-168.el9_6.23"
  }, {
    "product_name" : "Red Hat Ceph Storage 7",
    "release_date" : "2025-12-01T00:00:00Z",
    "advisory" : "RHSA-2025:22529",
    "cpe" : "cpe:/a:redhat:ceph_storage:7::el9",
    "package" : "rhceph/rhceph-7-rhel9:sha256:4d2f9dc5b2b33ee1c77bbfabcbbb9f4d94d343b04c4de2e4f8b3b81a1f0fd2fe"
  }, {
    "product_name" : "Red Hat Discovery 2",
    "release_date" : "2025-08-20T00:00:00Z",
    "advisory" : "RHSA-2025:14186",
    "cpe" : "cpe:/a:redhat:discovery:2::el9",
    "package" : "discovery/discovery-server-rhel9:sha256:6464f1f591001fd514a87e3c7347d2ce709b9c97edaad2d0d649ae69499049e9"
  }, {
    "product_name" : "Red Hat Insights proxy 1.5",
    "release_date" : "2025-08-07T00:00:00Z",
    "advisory" : "RHSA-2025:13335",
    "cpe" : "cpe:/a:redhat:insights_proxy:1.5::el9",
    "package" : "insights-proxy/insights-proxy-container-rhel9:sha256:c26d589f12647890b67aaa986f54d3f7c6f7f2563fb5a73f38d559e6138739d7"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.5.1",
    "release_date" : "2025-08-11T00:00:00Z",
    "advisory" : "RHSA-2025:13622",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
    "package" : "rhosdt/jaeger-agent-rhel8:sha256:2a359b16651cf20b9e37faabc6f57753744c59103979670260e263df2857da47"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.5.1",
    "release_date" : "2025-08-11T00:00:00Z",
    "advisory" : "RHSA-2025:13622",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
    "package" : "rhosdt/jaeger-all-in-one-rhel8:sha256:02d88da5fdc965b3759b7c74667dc93a374dc379719456a2a9c0ef15ac36d656"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.5.1",
    "release_date" : "2025-08-11T00:00:00Z",
    "advisory" : "RHSA-2025:13622",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
    "package" : "rhosdt/jaeger-collector-rhel8:sha256:260572b783d27d50a2dcdcac09a1fe15358c0fa5f85de93ce5fd8321cd81a0fa"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.5.1",
    "release_date" : "2025-08-11T00:00:00Z",
    "advisory" : "RHSA-2025:13622",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
    "package" : "rhosdt/jaeger-es-index-cleaner-rhel8:sha256:783a10c95edcb5c5cb8394b796f27dbfbb5ac6e1ee3baaa27d6c43f411ad6045"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.5.1",
    "release_date" : "2025-08-11T00:00:00Z",
    "advisory" : "RHSA-2025:13622",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
    "package" : "rhosdt/jaeger-es-rollover-rhel8:sha256:39b2d56b8f0eb3b539697fc387ae84230182c7e8cf5c184b8ee6c02e29386120"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.5.1",
    "release_date" : "2025-08-11T00:00:00Z",
    "advisory" : "RHSA-2025:13622",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
    "package" : "rhosdt/jaeger-ingester-rhel8:sha256:0932824cfd76c0e3d80f6e5b81312405b4a6a670d715144fc4d08bdb3a3cf962"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.5.1",
    "release_date" : "2025-08-11T00:00:00Z",
    "advisory" : "RHSA-2025:13622",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
    "package" : "rhosdt/jaeger-operator-bundle:sha256:264613b2add0f32e5f537ee7cf9ba8019e5e9a347fdf20bc3de8d1678157ba66"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.5.1",
    "release_date" : "2025-08-11T00:00:00Z",
    "advisory" : "RHSA-2025:13622",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
    "package" : "rhosdt/jaeger-query-rhel8:sha256:2509c7cc0bdf6d001442d2e83e21925b09a59c4b05eef81e98af93327f6f6c6d"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.5.1",
    "release_date" : "2025-08-11T00:00:00Z",
    "advisory" : "RHSA-2025:13622",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.5::el8",
    "package" : "rhosdt/jaeger-rhel8-operator:sha256:c6f9ee5f306766c0502419fe691e9e14aad8b0d1a4ced7ff9b1738c272fba80b"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Fix deferred",
    "package_name" : "compat-glibc",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Fix deferred",
    "package_name" : "glibc",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Fix deferred",
    "package_name" : "nss_db",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Fix deferred",
    "package_name" : "compat-glibc",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Fix deferred",
    "package_name" : "glibc",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "rhcos",
    "cpe" : "cpe:/a:redhat:openshift:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-8058\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-8058\nhttps://sourceware.org/bugzilla/show_bug.cgi?id=33185\nhttps://sourceware.org/git/?p=glibc.git;a=commit;h=3ff17af18c38727b88d9115e536c069e6b5d601f" ],
  "name" : "CVE-2025-8058",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}