CVE Vulnerabilities

CVE-2025-36083

Improper Clearing of Heap Memory Before Release ('Heap Inspection')

Published: Oct 28, 2025 | Modified: Oct 31, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM Concert Software

1.0.0 through 2.0.0 could allow a local user to obtain sensitive information from buffers due to improper clearing of heap memory before release.

Weakness

Using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory.

Affected Software

Name Vendor Start Version End Version
Concert Ibm 1.0.0 (including) 2.1.0 (excluding)

References