CVE-2025-14087
published 2025-12-10CVE-2025-14087: A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.77%
51.4th percentile
A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glib2.0 | < glib2.0 2.74.6-2+deb12u8 (bookworm) | glib2.0 2.74.6-2+deb12u8 (bookworm) |
| gnome | glib | < 2.86.3 | 2.86.3 |
| msrc | azl3_glib_2.78.6-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_glib_2.78.6-6_on_azure_linux_3.0 | — | — |
| msrc | cbl2_glib_2.71.0-8_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_glib_2.71.0-9_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_ubuntu7.7HIGH
vendor_debian5.6MEDIUM
vendor_msrc5.6MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GNOME GLib GVariant Parser bytestring_parse/string_parse buffer overflow (EUVD-2025-202405 / Nessus ID 278740)
vuldb·2026-06-06·CVSS 9.8
CVE-2025-14087 [CRITICAL] GNOME GLib GVariant Parser bytestring_parse/string_parse buffer overflow (EUVD-2025-202405 / Nessus ID 278740)
A vulnerability, which was classified as critical, was found in GNOME GLib. This affects the function bytestring_parse/string_parse of the component GVariant Parser. The manipulation results in buffer overflow.
This vulnerability is cataloged as CVE-2025-14087. The attack may be launched remotely. There is no exploit available.
OSV
glib2.0 vulnerabilities
osv·2026-02-10·CVSS 7.7
CVE-2025-3360 [HIGH] glib2.0 vulnerabilities
glib2.0 vulnerabilities
USN-7942-1 fixed vulnerabilities in GLib. This update provides the
corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 20.04 LTS. CVE-2025-3360 only affected Ubuntu 18.04
LTS and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that GLib incorrectly handled escaping URI strings. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-13601)
It was discovered that GLib incorrectly parsed certain GVariants. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-14087)
It was discovered that GLib incorrectly parsed certain long invalid ISO
8601 timesta
OSV
glib2.0 vulnerabilities
osv·2026-01-06·CVSS 7.7
CVE-2025-13601 [HIGH] glib2.0 vulnerabilities
glib2.0 vulnerabilities
It was discovered that GLib incorrectly handled escaping URI strings. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-13601)
It was discovered that GLib incorrectly parsed certain GVariants. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-14087)
It was discovered that GLib incorrectly parsed certain long invalid ISO
8601 timestamps. An attacker could possibly use this issue to cause GLib to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-3360)
It was discovered that GLib incorrectly handled GString memory operations.
An a
GHSA
GHSA-frh9-7wfp-w73p: A flaw was found in GLib (Gnome Lib)
ghsa_unreviewed·2025-12-10
CVE-2025-14087 [MEDIUM] CWE-190 GHSA-frh9-7wfp-w73p: A flaw was found in GLib (Gnome Lib)
A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.
OSV
CVE-2025-14087: A flaw was found in GLib (Gnome Lib)
osv·2025-12-10·CVSS 9.8
CVE-2025-14087 [CRITICAL] CVE-2025-14087: A flaw was found in GLib (Gnome Lib)
A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.
Ubuntu
GLib vulnerabilities
vendor_ubuntu·2026-02-10·CVSS 7.7
CVE-2025-7039 [HIGH] GLib vulnerabilities
Title: GLib vulnerabilities
Summary: Several security issues were fixed in GLib.
USN-7942-1 fixed vulnerabilities in GLib. This update provides the
corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 20.04 LTS. CVE-2025-3360 only affected Ubuntu 18.04
LTS and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that GLib incorrectly handled escaping URI strings. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-13601)
It was discovered that GLib incorrectly parsed certain GVariants. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-14087)
It was discovered that GLi
Ubuntu
GLib vulnerabilities
vendor_ubuntu·2026-01-06·CVSS 7.7
CVE-2025-14087 [HIGH] GLib vulnerabilities
Title: GLib vulnerabilities
Summary: Several security issues were fixed in GLib.
It was discovered that GLib incorrectly handled escaping URI strings. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-13601)
It was discovered that GLib incorrectly parsed certain GVariants. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-14087)
It was discovered that GLib incorrectly parsed certain long invalid ISO
8601 timestamps. An attacker could possibly use this issue to cause GLib to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-3360)
It was discovered tha
Microsoft
Glib: glib: buffer underflow in gvariant parser leads to heap corruption
vendor_msrc·2025-12-09·CVSS 5.6
CVE-2025-14087 [MEDIUM] CWE-190 Glib: glib: buffer underflow in gvariant parser leads to heap corruption
Glib: glib: buffer underflow in gvariant parser leads to heap corruption
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Red Hat
glib: GLib: Buffer underflow in GVariant parser leads to heap corruption
vendor_redhat·2025-12-05·CVSS 5.6
CVE-2025-14087 [MEDIUM] CWE-190 glib: GLib: Buffer underflow in GVariant parser leads to heap corruption
glib: GLib: Buffer underflow in GVariant parser leads to heap corruption
A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.
A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.
Statement: The highest threat is to system availability due to potential application crashes when processing maliciously crafted input strings through GLib's GVariant parser. This issue affects ap
Debian
CVE-2025-14087: glib2.0 - A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacke...
vendor_debian·2025·CVSS 5.6
CVE-2025-14087 [MEDIUM] CVE-2025-14087: glib2.0 - A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacke...
A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.
Scope: local
bookworm: resolved (fixed in 2.74.6-2+deb12u8)
bullseye: resolved (fixed in 2.66.8-1+deb11u7)
forky: resolved (fixed in 2.86.3-1)
sid: resolved (fixed in 2.86.3-1)
trixie: resolved (fixed in 2.84.4-3~deb13u2)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-14087 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.6
CVE-2025-14087 [MEDIUM] CVE-2025-14087 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14087 :
NixOS vulnerability analysis and mitigation
A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.
Source : NVD
## 9.8
Score
Published December 10, 2025
Severity CRITICAL
CNA Score 5.6
Affected Technologies
NixOS
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 46
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
glib2-doc
rpm-ostree
Sources
NVD
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.
Bugzilla
CVE-2025-14087 glib: GLib: Buffer underflow in GVariant parser leads to heap corruption
bugzilla·2025-12-05·CVSS 9.8
CVE-2025-14087 [CRITICAL] CVE-2025-14087 glib: GLib: Buffer underflow in GVariant parser leads to heap corruption
CVE-2025-14087 glib: GLib: Buffer underflow in GVariant parser leads to heap corruption
A buffer-underflow vulnerability exists in GLib’s GVariant parser, specifically within bytestring_parse() and string_parse(). The parser uses signed 32-bit integers (gint) as loop indices (i and j). When extremely large strings are parsed, these counters overflow into negative values, causing the parser to write to memory before the start of the allocated buffer (str[j++]). This results in a classic out-of-bounds write condition. Because GVariant parsing is often performed on attacker-influenced data, a remote attacker can trigger heap corruption, causing a crash or potentially achieving code execution. This flaw has been confirmed by maintainers and patched upstream.
Discussion:
The current state pe
https://access.redhat.com/errata/RHSA-2026:15953https://access.redhat.com/errata/RHSA-2026:15969https://access.redhat.com/errata/RHSA-2026:15971https://access.redhat.com/errata/RHSA-2026:19148https://access.redhat.com/errata/RHSA-2026:19361https://access.redhat.com/errata/RHSA-2026:19452https://access.redhat.com/errata/RHSA-2026:19457https://access.redhat.com/errata/RHSA-2026:19459https://access.redhat.com/errata/RHSA-2026:19460https://access.redhat.com/errata/RHSA-2026:19523https://access.redhat.com/errata/RHSA-2026:19524https://access.redhat.com/errata/RHSA-2026:19565https://access.redhat.com/errata/RHSA-2026:19566https://access.redhat.com/errata/RHSA-2026:19567https://access.redhat.com/errata/RHSA-2026:21275https://access.redhat.com/errata/RHSA-2026:22634https://access.redhat.com/errata/RHSA-2026:25096https://access.redhat.com/errata/RHSA-2026:29197https://access.redhat.com/errata/RHSA-2026:7461https://access.redhat.com/security/cve/CVE-2025-14087https://bugzilla.redhat.com/show_bug.cgi?id=2419093https://gitlab.gnome.org/GNOME/glib/-/issues/3834
2025-12-10
Published