CVE Vulnerabilities

CVE-2025-1759

Improper Clearing of Heap Memory Before Release ('Heap Inspection')

Published: Aug 18, 2025 | Modified: Aug 21, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.

Weakness

Using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory.

Affected Software

Name Vendor Start Version End Version
Concert Ibm 1.0.0 (including) 2.0.0 (excluding)

References