CVE-2025-0395: exploitation status and patch state
CVE-2025-0395 · CVSS 6.2 MEDIUM · EPSS <1%
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
Is CVE-2025-0395 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at <1%.
Public exploit code: none found in monitored sources.