Security readout for executives and security teams
Plain-English summary
CVE-2025-3359 is a gnuplot flaw that can cause a segmentation fault, disrupting availability of the local process. Red Hat rates it medium. The business impact is mainly denial of service where gnuplot is installed or used in workflows that process data locally.
Executive priority
Treat as a moderate availability issue. Prioritize environments where gnuplot supports reporting, scientific, engineering, or automated data-processing workflows. It is not currently supported by the sources as an actively exploited or data-compromise vulnerability.
Technical view
The issue is described as a segmentation fault in IO_str_init_static_internal, mapped to CWE-754. CVSS 3.1 is 6.2 with local attack vector, low complexity, no privileges, no user interaction, unchanged scope, and high availability impact only. Red Hat lists RHEL 7 and 8 gnuplot as affected; RHEL 6 status is unknown.
Likely exposure
Exposure is most likely on Linux systems with gnuplot installed, especially Red Hat Enterprise Linux 7 and 8 according to Red Hat’s affected list. Systems without gnuplot, or where it is not reachable by local users or automated jobs, have lower practical exposure.
Exploitation context
The provided sources do not show active exploitation, public weaponization, or CISA KEV listing. The CVSS vector indicates local exploitation affecting availability, not remote code execution or data theft. Practical risk increases if untrusted local inputs are processed by gnuplot in automated pipelines.
Researcher notes
Evidence is limited to vendor and issue-tracking descriptions. The sources identify the crash location and availability impact but do not provide a named fixed version in the supplied bundle. Avoid assuming exploitability beyond local denial of service unless vendor details expand.
Mitigation direction
Check Red Hat and gnuplot guidance for fixed package availability.
Prioritize updates on RHEL 7 and 8 systems running gnuplot.
Limit gnuplot processing of untrusted inputs where feasible.
Monitor vendor advisories for RHEL 6 status clarification.
Validation and detection
Inventory systems with the gnuplot package installed.
Map installed gnuplot instances to RHEL 7 and 8 exposure.
Review vendor advisories for package status and fixes.
Check crash logs for gnuplot segmentation faults referencing IO_str_init_static_internal.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-754: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-754 · source CWE mapping
Improper Check for Unusual or Exceptional Conditions
Improper Check for Unusual or Exceptional Conditions represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.