Description
A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.
Problem types
Integer Overflow or Wraparound
Product status
Timeline
| 2025-12-05: | Reported to Red Hat. |
| 2025-12-05: | Made public. |
Credits
Red Hat would like to thank Sovereign Tech Resilience program (Sovereign Tech Agency) and treeplus for reporting this issue.
References
access.redhat.com/security/cve/CVE-2025-14087
bugzilla.redhat.com/show_bug.cgi?id=2419093 (RHBZ#2419093)