CVE-2025-13601
7.7
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Exploitability: 2.5 / Impact: 5.2
Source: secalert@redhat.com (Secondary)
Description
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.
Affected (102)
Products: Redhat: Codeready Linux Builder, Codeready Linux Builder For Ibm Z Systems, Codeready Linux Builder For Power Little Endian, Codeready Linux Builder For X86 64, Enterprise Linux For Arm 64, Enterprise Linux For Ibm Z Systems, Enterprise Linux For Power Little Endian, Enterprise Linux For X86 64, Codeready Linux Builder For Arm64, Enterprise Linux Server Aus, Codeready Linux Builder For Arm64 Eus, Enterprise Linux For X86 64 Eus, Enterprise Linux Server For Power Little Endian, Enterprise Linux Server For Power Little Endian Eus, Codeready Linux Builder For Ibm Z Systems Eus, Codeready Linux Builder For Power Little Endian Eus, Codeready Linux Builder For X86 64 Eus, Enterprise Linux For Arm 64 Eus, Enterprise Linux For Ibm Z Systems Eus, Enterprise Linux For Power Little Endian Eus, Enterprise Linux Server Tus, Ceph Storage, Discovery, Openshift Container Platform, Openshift Container Platform For Arm64, Openshift Container Platform For Ibm Z, Openshift Container Platform For Linuxone, Openshift Container Platform For Power · Gnome: Glib
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.0 | |
| Version 9.0_s390x | |
| Version 9.0_ppc64le | |
| Version 9.0 | |
| Version 9.0 | |
| Version 9.0_s390x | |
| Version 9.0_ppc64le | |
| Version 9.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 | |
| Version 10.0_s390x | |
| Version 10.0_ppc64le | |
| Version 10.0 | |
| Version 10.0 | |
| Version 10.0_s390x | |
| Version 10.0_ppc64le | |
| Version 10.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 | |
| Version 8.0_s390x | |
| Version 8.0_ppc64le | |
| Version 8.0 | |
| Version 8.0 | |
| Version 8.0_s390x | |
| Version 8.0_ppc64le | |
| Version 8.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.2 | |
| Version 9.2_s390x | |
| Version 9.2_ppc64le | |
| Version 9.2 | |
| Version 9.2 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.4 | |
| Version 9.4_s390x | |
| Version 9.4_ppc64le | |
| Version 9.4 | |
| Version 9.4 | |
| Version 9.4_s390x | |
| Version 9.4_ppc64le | |
| Version 9.4 | |
| Version 9.4 | |
| Version 9.4 | |
| Version 9.4_ppc64le | |
| Version 9.4_ppc64le |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 | |
| Version 10.0_s390x | |
| Version 10.0_ppc64le | |
| Version 10.0 | |
| Version 10.0 | |
| Version 10.0_s390x | |
| Version 10.0_ppc64le | |
| Version 10.0 | |
| Version 10.0_ppc64le |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.6 | |
| Version 9.6_s390x | |
| Version 9.6_ppc64le | |
| Version 9.6 | |
| Version 9.6 | |
| Version 9.6_s390x | |
| Version 9.6_ppc64le | |
| Version 9.6_ppc64le | |
| Version 9.6 | |
| Version 9.6 | |
| Version 9.6 | |
| Version 9.6_ppc64le |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.6 | |
| Version 8.6 | |
| Version 8.6 | |
| Version 8.6_ppc64le | |
| Version 8.6 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.8 | |
| Version 8.8 | |
| Version 8.8_ppc64le | |
| Version 8.8 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.4 | |
| Version 8.4 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.2 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 | |
| Version 2.0 |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.12 | |
| Version 4.12 | |
| Version 4.12 | |
| Version 4.12 | |
| Version 4.12 |
References (33)
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Issue TrackingVendor Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Timeline
No history available yet.