CVE-2025-14087

medium
Published 2025-12-10 Β· Modified 2026-06-02
CVSS v3
5.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.6

Description

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.

Predictions

Exploit likelihood
66%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description glib: GLib: Buffer underflow in GVariant parser leads to heap corruption Red Hat statement The highest threat is to system availability due to potential application crashes when processing maliciously crafted input strings through GLib's GVariant parser. This issue affects applications that utilize g_variant_parse() on untrusted data, leading to memory corruption and possible denial…

Description

glib: GLib: Buffer underflow in GVariant parser leads to heap corruption

Red Hat statement

The highest threat is to system availability due to potential application crashes when processing maliciously crafted input strings through GLib's GVariant parser. This issue affects applications that utilize g_variant_parse() on untrusted data, leading to memory corruption and possible denial of service.

CVSS v3: 5.6 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10glib2-0:2.80.4-10.el10_1.13RHSA-2026:159692026-05-11T00:00:00Z
Red Hat Enterprise Linux 10glib2-0:2.80.4-12.el10_2.13RHSA-2026:191482026-05-19T00:00:00Z
Red Hat Enterprise Linux 10.0 Extended Update Supportglib2-0:2.80.4-4.el10_0.9RHSA-2026:195672026-05-20T00:00:00Z
Red Hat Enterprise Linux 7 Extended Lifecycle Supportglib2-0:2.56.1-12.el7_9RHSA-2026:195662026-05-20T00:00:00Z
Red Hat Enterprise Linux 8glib2-0:2.56.4-169.el8_10RHSA-2026:159532026-05-11T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportglib2-0:2.56.4-10.el8_4.5RHSA-2026:195652026-05-20T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onglib2-0:2.56.4-10.el8_4.5RHSA-2026:195652026-05-20T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportglib2-0:2.56.4-158.el8_6.5RHSA-2026:195242026-05-20T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Serviceglib2-0:2.56.4-158.el8_6.5RHSA-2026:195242026-05-20T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionsglib2-0:2.56.4-158.el8_6.5RHSA-2026:195242026-05-20T00:00:00Z
Red Hat Enterprise Linux 8.8 Telecommunications Update Serviceglib2-0:2.56.4-165.el8_8RHSA-2026:195232026-05-20T00:00:00Z
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionsglib2-0:2.56.4-165.el8_8RHSA-2026:195232026-05-20T00:00:00Z
Red Hat Enterprise Linux 9glib2-0:2.68.4-18.el9_7.2RHSA-2026:159712026-05-11T00:00:00Z
Red Hat Enterprise Linux 9glib2-0:2.68.4-19.el9_8.1RHSA-2026:193612026-05-19T00:00:00Z
Red Hat Enterprise Linux 9glib2-0:2.68.4-18.el9_7.2RHSA-2026:159712026-05-11T00:00:00Z
Red Hat Enterprise Linux 9glib2-0:2.68.4-19.el9_8.1RHSA-2026:193612026-05-19T00:00:00Z
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutionsglib2-0:2.68.4-5.el9_0.5RHSA-2026:194592026-05-20T00:00:00Z
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutionsglib2-0:2.68.4-7.el9_2.5RHSA-2026:194602026-05-20T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportglib2-0:2.68.4-14.el9_4.6RHSA-2026:194522026-05-20T00:00:00Z
Red Hat Enterprise Linux 9.6 Extended Update Supportglib2-0:2.68.4-16.el9_6.5RHSA-2026:194572026-05-20T00:00:00Z
Red Hat Hardened Imagesglib2-main-2.88.0-1.1.hum1RHSA-2026:74612026-04-10T00:00:00Z
Red Hat Update Infrastructure 5rhui5/cds-rhel9:1779798159RHSA-2026:212752026-05-27T00:00:00Z
Red Hat Update Infrastructure 5rhui5/haproxy-rhel9:1779798164RHSA-2026:212752026-05-27T00:00:00Z
Red Hat Update Infrastructure 5rhui5/installer-rhel9:1779798165RHSA-2026:212752026-05-27T00:00:00Z
Red Hat Update Infrastructure 5rhui5/rhua-rhel9:1779798222RHSA-2026:212752026-05-27T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 10bootcNot affected
Red Hat Enterprise Linux 10glycin-loadersNot affected
Red Hat Enterprise Linux 10loupeNot affected
Red Hat Enterprise Linux 10mingw-glib2Affected
Red Hat Enterprise Linux 10papersNot affected
Red Hat Enterprise Linux 10rpm-ostreeNot affected
Red Hat Enterprise Linux 6glib2Affected
Red Hat Enterprise Linux 8librsvg2Not affected
Red Hat Enterprise Linux 8mingw-glib2Affected
Red Hat Enterprise Linux 9bootcNot affected
Red Hat Enterprise Linux 9librsvg2Not affected
Red Hat Enterprise Linux 9mingw-glib2Will not fix

Apply commands

bash fix
Apply RHSA-2026:15969 for Red Hat Enterprise Linux 10
yum update -y glib2
# or:
dnf upgrade -y glib2

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 10Not affected
redhatRed Hat Enterprise Linux 10Not affected
redhatRed Hat Enterprise Linux 10Not affected
redhatRed Hat Enterprise Linux 10Affected
redhatRed Hat Enterprise Linux 10Not affected
redhatRed Hat Enterprise Linux 10Not affected
redhatRed Hat Enterprise Linux 6Affected
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat Enterprise Linux 9Not affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
redhat Red Hat Mixed 6 releases
VersionStatusFixed in
10.0 Affected β€”
9.0 Affected β€”
9 Fixed β€”
8.0 Affected β€”
8 Fixed β€”
7.0 Affected β€”
almalinux AlmaLinux Fixed 2 releases
VersionStatusFixed in
9 Fixed glib2-devel-2.68.4-18.el9_7.2.aarch64.rpm
8 Fixed glib2-2.56.4-169.el8_10.i686.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.84.4-3~deb13u2
sid Fixed 2.86.3-1
forky Fixed 2.86.3-1
bullseye Fixed 2.66.8-1+deb11u7
bookworm Fixed 2.74.6-2+deb12u8
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
9 Fixed β€”

Application impact

VendorProductVersionsFixed
gnomeglib{"endExcluding":"2.86.3"}2.86.3

References

CWEs

CWE-190

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.