Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
The product uses or accesses a resource that has not been initialized.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Glibc | Gnu | 2.0 (including) | 2.43 (excluding) |
| Eglibc | Ubuntu | esm-infra-legacy/trusty | * |
| Glibc | Ubuntu | devel | * |
| Glibc | Ubuntu | esm-infra/bionic | * |
| Glibc | Ubuntu | esm-infra/focal | * |
| Glibc | Ubuntu | esm-infra/xenial | * |
| Glibc | Ubuntu | jammy | * |
| Glibc | Ubuntu | noble | * |
| Glibc | Ubuntu | questing | * |
| Glibc | Ubuntu | upstream | * |