CVE Vulnerabilities

CVE-2025-33101

Improper Clearing of Heap Memory Before Release ('Heap Inspection')

Published: Feb 17, 2026 | Modified: Feb 18, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Concert 1.0.0 through 2.1.0 could allow an attacker to obtain sensitive information using man in the middle techniques due to improper clearing of heap memory.

Weakness

Using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory.

Affected Software

NameVendorStart VersionEnd Version
ConcertIbm1.0.0 (including)2.2.0 (excluding)

References