CVE-2025-5899

MEDIUM

GNU PSPP - Use-After-Free in parse_variables_option

Title source: llm
STIX 2.1

Description

A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to free of memory not on the heap. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

References (6)

Core 6
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.311671
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.311671
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.586106
Various Sources product
https://www.gnu.org/

Scores

CVSS v3 5.3
EPSS 0.0007
EPSS Percentile 21.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-590
Status published
Products (1)
GNU/PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb
Published Jun 09, 2025
Tracked Since Feb 18, 2026