Logo
vulnerabilityCVE-2025-2588
Name
CVE-2025-2588
Source
NVD ( link)Debian ( link)
Description
A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic. This vulnerability affects the function re_case_expand of the file src/fa.c. The manipulation of the argument re leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
augeas
Patched

Vulnerability Ratings#


4.8
CVSSv4
3.3
CVSSv31
3.3
CVSSv31
1.7
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
1.14.1
Patched
openwrt
master
1.14.1-r1
Exploitable
openwrt
openwrt-25.12
1.14.1-r1
Exploitable
yocto
kirkstone
1.12.0
Not Affected
yocto
master
1.12.0
Not Affected
yocto
scarthgap
1.12.0
Not Affected

Resolved with patches#


augeas (buildroot:2025.02.x)

#
Title
Author
Resolve
1
CVE-2025-2588: return _REG_ENOSYS if no specific error was
Alexander Bokovoy <abbra@users.noreply.github.com>
CVE-2025-2588

augeas (buildroot:master)

#
Title
Author
Resolve
1
CVE-2025-2588: return _REG_ENOSYS if no specific error was
Alexander Bokovoy <abbra@users.noreply.github.com>
CVE-2025-2588