CVE-2025-6052
published 2025-06-13CVE-2025-6052: A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.42%
34.1th percentile
A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corruption.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glib2.0 | < glib2.0 2.84.3-1 (forky) | glib2.0 2.84.3-1 (forky) |
| gnome | glib | 2.75.3 – 2.84.3 | — |
| msrc | azl3_glib_2.78.6-3_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.7HIGH
vendor_ubuntu7.7HIGH
vendor_debian3.7LOW
vendor_msrc3.7LOW
vendor_oracle3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GNOME glib GString g_string_maybe_expand integer overflow (EUVD-2025-18285 / Nessus ID 240347)
vuldb·2026-06-10·CVSS 7.5
CVE-2025-6052 [HIGH] GNOME glib GString g_string_maybe_expand integer overflow (EUVD-2025-18285 / Nessus ID 240347)
A vulnerability, which was classified as critical, has been found in GNOME glib. The impacted element is the function g_string_maybe_expand of the component GString. Performing a manipulation results in integer overflow.
This vulnerability is known as CVE-2025-6052. Access to the local network is required for this attack. No exploit is available.
OSV
glib2.0 vulnerabilities
osv·2026-02-10·CVSS 7.7
CVE-2025-3360 [HIGH] glib2.0 vulnerabilities
glib2.0 vulnerabilities
USN-7942-1 fixed vulnerabilities in GLib. This update provides the
corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 20.04 LTS. CVE-2025-3360 only affected Ubuntu 18.04
LTS and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that GLib incorrectly handled escaping URI strings. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-13601)
It was discovered that GLib incorrectly parsed certain GVariants. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-14087)
It was discovered that GLib incorrectly parsed certain long invalid ISO
8601 timesta
OSV
glib2.0 vulnerabilities
osv·2026-01-06·CVSS 7.7
CVE-2025-13601 [HIGH] glib2.0 vulnerabilities
glib2.0 vulnerabilities
It was discovered that GLib incorrectly handled escaping URI strings. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-13601)
It was discovered that GLib incorrectly parsed certain GVariants. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-14087)
It was discovered that GLib incorrectly parsed certain long invalid ISO
8601 timestamps. An attacker could possibly use this issue to cause GLib to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-3360)
It was discovered that GLib incorrectly handled GString memory operations.
An a
GHSA
GHSA-99rj-3595-5frj: A flaw was found in how GLib’s GString manages memory when adding data to strings
ghsa_unreviewed·2025-06-13
CVE-2025-6052 [LOW] CWE-190 GHSA-99rj-3595-5frj: A flaw was found in how GLib’s GString manages memory when adding data to strings
A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corruption.
OSV
CVE-2025-6052: A flaw was found in how GLib’s GString manages memory when adding data to strings
osv·2025-06-13·CVSS 7.5
CVE-2025-6052 [HIGH] CVE-2025-6052: A flaw was found in how GLib’s GString manages memory when adding data to strings
A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corruption.
Ubuntu
GLib vulnerabilities
vendor_ubuntu·2026-02-10·CVSS 7.7
CVE-2025-7039 [HIGH] GLib vulnerabilities
Title: GLib vulnerabilities
Summary: Several security issues were fixed in GLib.
USN-7942-1 fixed vulnerabilities in GLib. This update provides the
corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 20.04 LTS. CVE-2025-3360 only affected Ubuntu 18.04
LTS and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that GLib incorrectly handled escaping URI strings. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-13601)
It was discovered that GLib incorrectly parsed certain GVariants. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-14087)
It was discovered that GLi
Oracle
Oracle Oracle Java SE Risk Matrix: JavaFX (glibc) — CVE-2025-6052
vendor_oracle·2026-01-15·CVSS 3.7
CVE-2025-6052 [LOW] Oracle Oracle Java SE Risk Matrix: JavaFX (glibc) — CVE-2025-6052
Oracle Oracle Java SE Risk Matrix: JavaFX (glibc) vulnerability
CVE: CVE-2025-6052
CVSS: 3.7
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Ubuntu
GLib vulnerabilities
vendor_ubuntu·2026-01-06·CVSS 7.7
CVE-2025-14087 [HIGH] GLib vulnerabilities
Title: GLib vulnerabilities
Summary: Several security issues were fixed in GLib.
It was discovered that GLib incorrectly handled escaping URI strings. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-13601)
It was discovered that GLib incorrectly parsed certain GVariants. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-14087)
It was discovered that GLib incorrectly parsed certain long invalid ISO
8601 timestamps. An attacker could possibly use this issue to cause GLib to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-3360)
It was discovered tha
Red Hat
glib: Integer overflow in g_string_maybe_expand() leading to potential buffer overflow in GLib GString
vendor_redhat·2025-06-13·CVSS 3.7
CVE-2025-6052 [LOW] CWE-190 glib: Integer overflow in g_string_maybe_expand() leading to potential buffer overflow in GLib GString
glib: Integer overflow in g_string_maybe_expand() leading to potential buffer overflow in GLib GString
A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corruption.
A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of th
Microsoft
Glib: integer overflow in g_string_maybe_expand() leading to potential buffer overflow in glib gstring
vendor_msrc·2025-06-10·CVSS 3.7
CVE-2025-6052 [LOW] CWE-190 Glib: integer overflow in g_string_maybe_expand() leading to potential buffer overflow in glib gstring
Glib: integer overflow in g_string_maybe_expand() leading to potential buffer overflow in glib gstring
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediatio
Debian
CVE-2025-6052: glib2.0 - A flaw was found in how GLib’s GString manages memory when adding data to string...
vendor_debian·2025·CVSS 3.7
CVE-2025-6052 [LOW] CVE-2025-6052: glib2.0 - A flaw was found in how GLib’s GString manages memory when adding data to string...
A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corruption.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 2.84.3-1)
sid: resolved (fixed in 2.84.3-1)
trixie: resolved (fixed in 2.84.3-1)
No detection rules found.
No public exploits indexed.
2025-06-13
Published