CVE-2025-6052

Name
CVE-2025-6052
Description
A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corruption.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
vdb-entry https://access.redhat.com/security/cve/CVE-2025-6052
issue-tracking https://bugzilla.redhat.com/show_bug.cgi?id=2372666

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:* glib >= 2.75.3 <= 2.84.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
glib edge-main 2.84.3-r0 team/gnome <pabloyoyoista@postmarketos.org> possibly vulnerable
glib edge-main 2.84.2-r1 team/gnome <pabloyoyoista@postmarketos.org> possibly vulnerable
glib edge-main 2.84.2-r0 team/gnome <pabloyoyoista@postmarketos.org> possibly vulnerable
glib edge-main 2.84.1-r0 team/gnome <pabloyoyoista@postmarketos.org> possibly vulnerable
glib edge-main 2.84.0-r0 team/gnome <pabloyoyoista@postmarketos.org> possibly vulnerable
glib edge-main 2.82.5-r1 team/gnome <pabloyoyoista@postmarketos.org> possibly vulnerable
glib edge-main 2.82.5-r0 Pablo Correa Gómez <pabloyoyoista@postmarketos.org> possibly vulnerable
glib edge-main 2.82.4-r0 Pablo Correa Gómez <pabloyoyoista@postmarketos.org> possibly vulnerable
glib edge-main 2.82.3-r0 Pablo Correa Gómez <pabloyoyoista@postmarketos.org> possibly vulnerable
glib edge-main 2.82.2-r1 Pablo Correa Gómez <pabloyoyoista@postmarketos.org> possibly vulnerable
glib edge-main 2.82.2-r0 Pablo Correa Gómez <pabloyoyoista@postmarketos.org> possibly vulnerable
glib edge-main 2.80.1-r0 Pablo Correa Gómez <ablocorrea@hotmail.com> possibly vulnerable
glib 3.22-main 2.84.3-r0 team/gnome <pabloyoyoista@postmarketos.org> possibly vulnerable
glib 3.22-main 2.80.1-r0 None possibly vulnerable
glib 3.21-main 2.82.5-r0 Pablo Correa Gómez <pabloyoyoista@postmarketos.org> possibly vulnerable
glib 3.21-main 2.82.4-r0 Pablo Correa Gómez <pabloyoyoista@postmarketos.org> possibly vulnerable
glib 3.21-main 2.82.3-r0 Pablo Correa Gómez <pabloyoyoista@postmarketos.org> possibly vulnerable
glib 3.21-main 2.82.2-r0 Pablo Correa Gómez <pabloyoyoista@postmarketos.org> possibly vulnerable
glib 3.21-main 2.80.1-r0 None possibly vulnerable
glib 3.20-main 2.80.5-r0 Pablo Correa Gómez <ablocorrea@hotmail.com> possibly vulnerable
glib 3.20-main 2.80.1-r0 None possibly vulnerable
glib 3.19-main 2.78.6-r0 Pablo Correa Gómez <ablocorrea@hotmail.com> possibly vulnerable
glib 3.19-main 2.78.5-r0 Pablo Correa Gómez <ablocorrea@hotmail.com> possibly vulnerable