---
title: "CVE-2025-5745\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2025-5745?format=md
keywords: index, follow
---

# CVE-2025-5745

Publication date 5 June 2025

Last updated 14 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.6 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2025-5745?format=md#impact-score)

Toggle side navigation

## Description

The strncmp implementation optimized for the Power10 processor in the GNU C
Library version 2.40 and later writes to vector registers v20 to v31
without saving contents from the caller (those registers are defined as
non-volatile registers by the powerpc64le ABI), resulting in overwriting of
its contents and potentially altering control flow of the caller, or
leaking the input strings to the function to other parts of the program.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2025-5745?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| eglibc | 25.04 plucky | Not in release |
| 24.10 oracular | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Not in release |
| 14.04 LTS trusty | Not affected |
| glibc | 25.04 plucky | Fixed 2.41-6ubuntu1.1 |
| 24.10 oracular | Ignored end of life, was needed |
| 24.04 LTS noble | Not affected |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2025-5745?format=md#patch-details)

## Notes

---

### [rodrigo-zaiden](https://launchpad.net/~rodrigo-zaiden)

limited to applications running on Power 10 hardware.
introduced on glibc-2.40 with commit:
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=23f0d81608d0ca6379894ef81670cf30af7fd081

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| glibc | * Upstream:   <https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=63c60101ce7c5eac42be90f698ba02099b41b965> * Upstream:   <https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=84bdbf8a6f2fdafd3661489dbb7f79835a52da82> * Upstream:   <https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=42a5a940c974d02540c8da26d6374c744d148cb9> |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.6 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | Low |
  | Integrity impact | Low |
  | Availability impact | Low |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.6 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-5745)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-5745)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2025-5745)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2025-5745)

### Related Ubuntu Security Notices (USN)

+ [USN-7634-1](https://usn.ubuntu.com/USN-7634-1)
+ GNU C Library vulnerabilities
+ 14 July 2025

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2025-5745>
* <https://sourceware.org/pipermail/libc-alpha/2025-June/167405.html>
