PT-2025-25431 · Glib+7 · Glib+7

Philip Withnall

·

Published

2025-01-01

·

Updated

2026-05-08

·

CVE-2025-6052

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GLib (affected versions not specified)
Description A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12627
AZL-63912
BDU:2025-12471
BIT-JAVA-2025-6052
BIT-JAVA-MIN-2025-6052
BIT-JRE-2025-6052
CVE-2025-6052
ECHO-B543-F20A-A5C6
JLSEC-2025-167
MGASA-2025-0216
OESA-2025-1795
OESA-2025-1796
OESA-2025-1797
OPENSUSE-SU-2025:15221-1
SUSE-SU-2025:02167-1
SUSE-SU-2025:20508-1
SUSE-SU-2025:20673-1
SUSE-SU-2025_02167-1
USN-7942-1

Affected Products

Alt Linux
Astra Linux
Debian
Glib
Java Platform
Linuxmint
Suse
Ubuntu