Free of Memory not on the Heap
CVE-2025-5899
Summary
A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to free of memory not on the heap. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
- LOW
- LOCAL
- LOW
- UNCHANGED
- NONE
- LOW
- LOW
- LOW
CWE-590 - Free of Memory not on the Heap
The application calls free() on a pointer to memory that was not allocated using associated heap allocation functions such as malloc(), calloc(), or realloc().
References
Advisory Timeline
- Published