CVE-2025-13601
published 2025-11-26CVE-2025-13601: A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to…
PriorityP343high7.7CVSS 3.1
AVLACLPRNUINSUCNIHAH
EPSS
0.31%
23.3th percentile
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.
Affected
105 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glib2.0 | < glib2.0 2.74.6-2+deb12u8 (bookworm) | glib2.0 2.74.6-2+deb12u8 (bookworm) |
| gnome | glib | < 2.86.3 | 2.86.3 |
| msrc | azl3_glib_2.78.6-4_on_azure_linux_3.0 | — | — |
| msrc | cbl2_glib_2.71.0-7_on_cbl_mariner_2.0 | — | — |
| redhat | ceph_storage | — | — |
| redhat | codeready_linux_builder | — | — |
| redhat | codeready_linux_builder_for_arm64 | — | — |
| redhat | codeready_linux_builder_for_arm64 | — | — |
| redhat | codeready_linux_builder_for_arm64 | — | — |
| redhat | codeready_linux_builder_for_arm64_eus | — | — |
| redhat | codeready_linux_builder_for_arm64_eus | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems_eus | — | — |
| redhat | codeready_linux_builder_for_power_little_endian | — | — |
| redhat | codeready_linux_builder_for_power_little_endian | — | — |
| redhat | codeready_linux_builder_for_power_little_endian | — | — |
| redhat | codeready_linux_builder_for_power_little_endian | — | — |
| redhat | codeready_linux_builder_for_power_little_endian | — | — |
| redhat | codeready_linux_builder_for_power_little_endian_eus | — | — |
| redhat | codeready_linux_builder_for_x86_64 | — | — |
| redhat | codeready_linux_builder_for_x86_64 | — | — |
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
osv7.7HIGH
vendor_debian7.7HIGH
vendor_msrc7.7HIGH
vendor_redhat7.7HIGH
vendor_ubuntu7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
glib2.0 vulnerabilities
osv·2026-02-10·CVSS 7.7
CVE-2025-3360 [HIGH] glib2.0 vulnerabilities
glib2.0 vulnerabilities
USN-7942-1 fixed vulnerabilities in GLib. This update provides the
corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 20.04 LTS. CVE-2025-3360 only affected Ubuntu 18.04
LTS and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that GLib incorrectly handled escaping URI strings. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-13601)
It was discovered that GLib incorrectly parsed certain GVariants. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-14087)
It was discovered that GLib incorrectly parsed certain long invalid ISO
8601 timesta
OSV
glib2.0 vulnerabilities
osv·2026-01-06·CVSS 7.7
CVE-2025-13601 [HIGH] glib2.0 vulnerabilities
glib2.0 vulnerabilities
It was discovered that GLib incorrectly handled escaping URI strings. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-13601)
It was discovered that GLib incorrectly parsed certain GVariants. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-14087)
It was discovered that GLib incorrectly parsed certain long invalid ISO
8601 timestamps. An attacker could possibly use this issue to cause GLib to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-3360)
It was discovered that GLib incorrectly handled GString memory operations.
An a
GHSA
GHSA-v6c5-9mp4-mwq4: A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function
ghsa_unreviewed·2025-11-26
CVE-2025-13601 [HIGH] CWE-190 GHSA-v6c5-9mp4-mwq4: A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.
OSV
CVE-2025-13601: A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function
osv·2025-11-26·CVSS 7.7
CVE-2025-13601 [HIGH] CVE-2025-13601: A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.
Ubuntu
GLib vulnerabilities
vendor_ubuntu·2026-02-10·CVSS 7.7
CVE-2025-7039 [HIGH] GLib vulnerabilities
Title: GLib vulnerabilities
Summary: Several security issues were fixed in GLib.
USN-7942-1 fixed vulnerabilities in GLib. This update provides the
corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 20.04 LTS. CVE-2025-3360 only affected Ubuntu 18.04
LTS and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that GLib incorrectly handled escaping URI strings. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-13601)
It was discovered that GLib incorrectly parsed certain GVariants. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-14087)
It was discovered that GLi
Ubuntu
GLib vulnerabilities
vendor_ubuntu·2026-01-06·CVSS 7.7
CVE-2025-14087 [HIGH] GLib vulnerabilities
Title: GLib vulnerabilities
Summary: Several security issues were fixed in GLib.
It was discovered that GLib incorrectly handled escaping URI strings. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-13601)
It was discovered that GLib incorrectly parsed certain GVariants. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-14087)
It was discovered that GLib incorrectly parsed certain long invalid ISO
8601 timestamps. An attacker could possibly use this issue to cause GLib to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-3360)
It was discovered tha
Red Hat
glib: Integer overflow in in g_escape_uri_string()
vendor_redhat·2025-11-24·CVSS 7.7
CVE-2025-13601 [HIGH] CWE-190 glib: Integer overflow in in g_escape_uri_string()
glib: Integer overflow in in g_escape_uri_string()
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the
Microsoft
Glib: integer overflow in in g_escape_uri_string()
vendor_msrc·2025-11-11·CVSS 7.7
CVE-2025-13601 [HIGH] CWE-190 Glib: integer overflow in in g_escape_uri_string()
Glib: integer overflow in in g_escape_uri_string()
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2025-13601: glib2.0 - A heap-based buffer overflow problem was found in glib through an incorrect calc...
vendor_debian·2025·CVSS 7.7
CVE-2025-13601 [HIGH] CVE-2025-13601: glib2.0 - A heap-based buffer overflow problem was found in glib through an incorrect calc...
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.
Scope: local
bookworm: resolved (fixed in 2.74.6-2+deb12u8)
bullseye: resolved (fixed in 2.66.8-1+deb11u7)
forky: resolved (fixed in 2.86.3-1)
sid: resolved (fixed in 2.86.3-1)
trixie: resolved (fixed in 2.84.4-3~deb13u2)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2026:0936https://access.redhat.com/errata/RHSA-2026:0975https://access.redhat.com/errata/RHSA-2026:0991https://access.redhat.com/errata/RHSA-2026:1323https://access.redhat.com/errata/RHSA-2026:1324https://access.redhat.com/errata/RHSA-2026:1326https://access.redhat.com/errata/RHSA-2026:1327https://access.redhat.com/errata/RHSA-2026:1465https://access.redhat.com/errata/RHSA-2026:1608https://access.redhat.com/errata/RHSA-2026:1624https://access.redhat.com/errata/RHSA-2026:1625https://access.redhat.com/errata/RHSA-2026:1626https://access.redhat.com/errata/RHSA-2026:1627https://access.redhat.com/errata/RHSA-2026:1652https://access.redhat.com/errata/RHSA-2026:1736https://access.redhat.com/errata/RHSA-2026:18344https://access.redhat.com/errata/RHSA-2026:18705https://access.redhat.com/errata/RHSA-2026:2064https://access.redhat.com/errata/RHSA-2026:2072https://access.redhat.com/errata/RHSA-2026:2485https://access.redhat.com/errata/RHSA-2026:2563https://access.redhat.com/errata/RHSA-2026:2633https://access.redhat.com/errata/RHSA-2026:2659https://access.redhat.com/errata/RHSA-2026:2671https://access.redhat.com/errata/RHSA-2026:2974https://access.redhat.com/errata/RHSA-2026:3415https://access.redhat.com/errata/RHSA-2026:4419https://access.redhat.com/errata/RHSA-2026:7461https://access.redhat.com/security/cve/CVE-2025-13601https://bugzilla.redhat.com/show_bug.cgi?id=2416741https://gitlab.gnome.org/GNOME/glib/-/issues/3827https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4914https://cert-portal.siemens.com/productcert/html/ssa-253495.html
2025-11-26
Published