CVE-2025-2588

Name
CVE-2025-2588
Description
A vulnerability has been found in Hercules Augeas 1.14.1 and classified as problematic. This vulnerability affects the function re_case_expand of the file src/fa.c. The manipulation of the argument re leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
issue-tracking https://github.com/hercules-team/augeas/issues/852
exploit https://github.com/hercules-team/augeas/issues/852#issue-2905999609
signature https://vuldb.com/?ctiid.300568
vdb-entry https://vuldb.com/?id.300568
third-party-advisory https://vuldb.com/?submit.517281

Match rules

CPE URI Source package Min version Max version
augeas == 1.14.1 == 1.14.1
cpe:2.3:a:augeas:augeas:1.14.1:*:*:*:*:*:*:* augeas == None == 1.14.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
augeas edge-main 1.14.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable