CVE Vulnerabilities

CVE-2025-36083

Improper Clearing of Heap Memory Before Release ('Heap Inspection')

Published: Oct 28, 2025 | Modified: Oct 31, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM Concert Software

1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap memory before release.

Weakness

Using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory.

Affected Software

NameVendorStart VersionEnd Version
ConcertIbm1.0.0 (including)2.1.0 (excluding)

References