CVE-2025-14087 Details
Description
A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.
A buffer-underflow vulnerability has been identified in GLib's GVariant parser, specifically in the bytestring_parse() and string_parse() functions. This vulnerability allows remote attackers to cause heap corruption, leading to application crashes or potentially executing arbitrary code. The issue arises when the parser processes maliciously crafted input strings, causing signed 32-bit integer loop indices to overflow into negative values. This overflow allows the parser to write to memory before the allocated buffer, creating an out-of-bounds write condition. The vulnerability is particularly concerning because GVariant parsing is often performed on data influenced by attackers, making it exploitable in real-world scenarios.
The vulnerability has been patched upstream, but users should check with their specific distribution for the availability of the fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gnome glib | < 2.86.3 |
CPE
Remediation
| |
| redhat enterprise linux | 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
24 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 25, 2026 | CVE Modified | [email protected] |
| Aug 3, 2026 | CVE Modified | [email protected] |
| Jul 13, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 24, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 10, 2026 | CVE Modified | [email protected] |
| Jun 2, 2026 | CVE Modified | [email protected] |
| May 27, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 20, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | CVE Modified | [email protected] |
| May 11, 2026 | CVE Modified | [email protected] |
| May 11, 2026 | CVE Modified | [email protected] |
| May 11, 2026 | CVE Modified | [email protected] |
| Apr 19, 2026 | CVE Modified | [email protected] |
| Mar 18, 2026 | CVE Modified | [email protected] |
| Feb 6, 2026 | Initial Analysis | [email protected] |
| Dec 10, 2025 | New CVE Received | [email protected] |