Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HDefault status
unaffected
Any version before 2.84.1
affected
Default status
unaffected
Default status
unaffected
Default status
unaffected
Default status
unaffected
Default status
unaffected
Default status
unaffected
Default status
unaffected
Default status
unaffected
Default status
unaffected
Default status
unaffected
Default status
unaffected
Default status
unaffected
Default status
unaffected
Default status
unaffected
Description
A flaw was found in GLib. A denial of service on Windows platforms may occur if an application attempts to spawn a program using long command lines.
Problem types
Improper Control of Generation of Code ('Code Injection')
Product status
Any version before 2.84.1
Timeline
| 2025-04-29: | Reported to Red Hat. |
| 2025-04-29: | Made public. |
References
access.redhat.com/security/cve/CVE-2025-4056
bugzilla.redhat.com/show_bug.cgi?id=2362826 (RHBZ#2362826)
gitlab.gnome.org/GNOME/glib/-/issues/3668