CVE-2025-4373 Details
Description
A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite.
A vulnerability exists in GLib versions prior to 2.84.2, where an integer overflow in the g_string_insert_unichar() function can occur. This overflow happens when a large position is specified for character insertion, causing the position to wrap around and underwrite the buffer. As a result, data may be improperly handled or corrupted.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 6, 2025CISA-ADP
Assessed May 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-124 | Buffer Underwrite ('Buffer Underflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GNOME GLib | < 2.84.2 (semver) |
CPE
Remediation
| |
| Red Hat Enterprise Linux | < 2.84.2 (semver) |
CPE
Remediation
| |
Change History
31 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | CVE Modified | [email protected] |
| Sep 7, 2026 | CVE Modified | [email protected] |
| Sep 6, 2026 | CVE Modified | [email protected] |
| Sep 5, 2026 | CVE Modified | siemens-SADP |
| Sep 5, 2026 | CVE Modified | [email protected] |
| Aug 25, 2026 | CVE Modified | [email protected] |
| Aug 17, 2026 | CVE Modified | [email protected] |
| Aug 16, 2026 | CVE Modified | [email protected] |
| Aug 16, 2026 | CVE Modified | [email protected] |
| Aug 12, 2026 | CVE Modified | [email protected] |
| Aug 9, 2026 | CVE Modified | [email protected] |
| Aug 9, 2026 | CVE Modified | [email protected] |
| Aug 4, 2026 | CVE Modified | [email protected] |
| Aug 2, 2026 | CVE Modified | [email protected] |
| Jul 19, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | siemens-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | CVE Modified | siemens-SADP |
| Sep 2, 2025 | CVE Modified | [email protected] |
| Aug 7, 2025 | CVE Modified | [email protected] |
| Jul 30, 2025 | CVE Modified | [email protected] |
| Jul 29, 2025 | CVE Modified | [email protected] |
| Jul 23, 2025 | CVE Modified | [email protected] |
| Jul 17, 2025 | CVE Modified | [email protected] |
| Jul 16, 2025 | CVE Modified | [email protected] |
| Jul 15, 2025 | CVE Modified | [email protected] |
| Jul 14, 2025 | CVE Modified | [email protected] |
| May 6, 2025 | New CVE Received | [email protected] |
Volerion