Home

Description

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.

PUBLISHED Reserved 2025-12-05 | Published 2025-12-10 | Updated 2025-12-10 | Assigner redhat




MEDIUM: 5.6CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Problem types

Integer Overflow or Wraparound

Product status

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
unknown

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Timeline

2025-12-05:Reported to Red Hat.
2025-12-05:Made public.

Credits

Red Hat would like to thank Sovereign Tech Resilience program (Sovereign Tech Agency) and treeplus for reporting this issue.

References

access.redhat.com/security/cve/CVE-2025-14087 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2419093 (RHBZ#2419093) issue-tracking

cve.org (CVE-2025-14087)

nvd.nist.gov (CVE-2025-14087)

Download JSON