CVE-2025-14512
published 2025-12-11CVE-2025-14512: A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib…
PriorityP434medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.52%
40.9th percentile
A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glib2.0 | < glib2.0 2.74.6-2+deb12u8 (bookworm) | glib2.0 2.74.6-2+deb12u8 (bookworm) |
| gnome | glib | < 2.86.3 | 2.86.3 |
| msrc | azl3_glib_2.78.6-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_glib_2.78.6-6_on_azure_linux_3.0 | — | — |
| msrc | cbl2_glib_2.71.0-8_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_glib_2.71.0-9_on_cbl_mariner_2.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow
vendor_redhat·2025-12-11·CVSS 6.5
CVE-2025-14512 [MEDIUM] CWE-190 glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow
glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow
A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.
A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.
Statement: This vulnerability is rated Moderate for Red Hat products because an integer overflow in GLib's GIO `escape_byte_string()` function can lead to a heap buffer overflow and denial-of-s
Microsoft
Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow
vendor_msrc·2025-12-09·CVSS 6.5
CVE-2025-14512 [MEDIUM] CWE-190 Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow
Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2025-14512: glib2.0 - A flaw was found in glib. This vulnerability allows a heap buffer overflow and d...
vendor_debian·2025·CVSS 6.5
CVE-2025-14512 [MEDIUM] CVE-2025-14512: glib2.0 - A flaw was found in glib. This vulnerability allows a heap buffer overflow and d...
A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.
Scope: local
bookworm: resolved (fixed in 2.74.6-2+deb12u8)
bullseye: resolved (fixed in 2.66.8-1+deb11u7)
forky: resolved (fixed in 2.86.3-1)
sid: resolved (fixed in 2.86.3-1)
trixie: resolved (fixed in 2.84.4-3~deb13u2)
VulDB
GNOME Glib Remote Fileystem escape_byte_string integer overflow (EUVD-2025-202664 / Nessus ID 278352)
vuldb·2026-06-06·CVSS 6.5
CVE-2025-14512 [MEDIUM] GNOME Glib Remote Fileystem escape_byte_string integer overflow (EUVD-2025-202664 / Nessus ID 278352)
A vulnerability, which was classified as critical, has been found in GNOME Glib. This impacts the function escape_byte_string of the component Remote Fileystem Handler. The manipulation leads to integer overflow.
This vulnerability is documented as CVE-2025-14512. The attack can be initiated remotely. There is not any exploit available.
OSV
CVE-2025-14512: A flaw was found in glib
osv·2025-12-11·CVSS 6.5
CVE-2025-14512 [MEDIUM] CVE-2025-14512: A flaw was found in glib
A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.
GHSA
GHSA-2p5v-p767-wqv5: A flaw was found in glib
ghsa_unreviewed·2025-12-11
CVE-2025-14512 [MEDIUM] CWE-190 GHSA-2p5v-p767-wqv5: A flaw was found in glib
A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-14512 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-14512 [MEDIUM] CVE-2025-14512 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14512 :
NixOS vulnerability analysis and mitigation
A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.
Source : NVD
## 6.5
Score
Published December 11, 2025
Severity MEDIUM
CNA Score 6.5
Affected Technologies
NixOS
CBL Mariner
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
glib2-lang
libgobject-2_0-0
Sources
NVD
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.2
Bugzilla
CVE-2025-14512 glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow
bugzilla·2025-12-11·CVSS 6.5
CVE-2025-14512 [MEDIUM] CVE-2025-14512 glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow
CVE-2025-14512 glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow
This vulnerability stems from an integer overflow in GLib’s GIO escape_byte_string() function, where the count of invalid characters is multiplied using a signed integer, resulting in a too-small memory allocation for escaped output. When a malicious file or remote filesystem supplies attribute values with a large number of invalid bytes, the subsequent escaping loop writes beyond the allocated buffer, triggering a heap buffer overflow and crashing the process.
https://access.redhat.com/errata/RHSA-2026:15953https://access.redhat.com/errata/RHSA-2026:15969https://access.redhat.com/errata/RHSA-2026:15971https://access.redhat.com/errata/RHSA-2026:19148https://access.redhat.com/errata/RHSA-2026:19361https://access.redhat.com/errata/RHSA-2026:19452https://access.redhat.com/errata/RHSA-2026:19457https://access.redhat.com/errata/RHSA-2026:19459https://access.redhat.com/errata/RHSA-2026:19460https://access.redhat.com/errata/RHSA-2026:19523https://access.redhat.com/errata/RHSA-2026:19524https://access.redhat.com/errata/RHSA-2026:19565https://access.redhat.com/errata/RHSA-2026:19567https://access.redhat.com/errata/RHSA-2026:21275https://access.redhat.com/errata/RHSA-2026:22634https://access.redhat.com/errata/RHSA-2026:25096https://access.redhat.com/errata/RHSA-2026:29197https://access.redhat.com/errata/RHSA-2026:7461https://access.redhat.com/security/cve/CVE-2025-14512https://bugzilla.redhat.com/show_bug.cgi?id=2421339https://gitlab.gnome.org/GNOME/glib/-/issues/3845
2025-12-11
Published