Integer overflow in Gnome GLib - CVE-2025-4373

 

Integer overflow in Gnome GLib - CVE-2025-4373

Published: May 27, 2025


Vulnerability identifier: #VU109848
CSH Severity: High
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-4373
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow within the g_string_insert_unichar() function in glib/gstring.c. A remote attacker can pass specially crafted data to the application, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Gnome GLib
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Sterling Connect:Direct Web Services
IBM Power Hardware Management Console (HMC)
Oracle Communications Cloud Native Core Certificate Management
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
Splunk Operator for Kubernetes Add-on
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
openEuler
Ubuntu
IBM Qradar SIEM
Storage Virtualize
Total Storage Service Console (TSSC) / TS4500 IMC
Robotic Process Automation for Cloud Pak
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
glib2 (Red Hat package)
libgmodule-2_0-0-debuginfo
libgio-2_0-0
glib2-tools
libgmodule-2_0-0
glib2-tools-debuginfo
libglib-2_0-0-debuginfo
libgio-2_0-0-debuginfo
libglib-2_0-0
glib2-debugsource
libgobject-2_0-0
libgobject-2_0-0-debuginfo
glib2.0 (Ubuntu package)
glib2
glib2-debuginfo
glib2-devel
glib2-help
glib2-doc
glib2-tests
glib2-static
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Virtualization
Red Hat OpenShift Container Platform
Red Hat Ceph Storage

How to mitigate CVE-2025-4373

Install updates from vendor's website.

Gnome GLib - update to 2.84.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.1
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.14.0.2, 6.4.0.3.0.2
IBM Qradar SIEM - update to 7.5.0 Update Pack 13 IF01
Storage Virtualize - addressed in versions 8.7.0.8, 9.1.0.2
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1060.0 SP2, 11.1.1110.0
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.5, 30.0.1
Red Hat OpenShift Serverless - update to 1
Ansible Automation Platform - update to 2.5
Multicluster Engine for Kubernetes - addressed in versions 2.6.8, 2.7.6, 2.8.3
Red Hat Advanced Cluster Management for Kubernetes - update to 2.13.4
glib2 (Red Hat package) - addressed in versions 2.56.4-10.el8_4.2, 2.56.4-166.el8_10, 2.68.4-5.el9_0.2, 2.68.4-7.el9_2.2, 2.68.4-14.el9_4.3, 2.68.4-16.el9_6.2
libgmodule-2_0-0-debuginfo - update to 2.62.6-150200.3.30.1
libgio-2_0-0 - update to 2.62.6-150200.3.30.1
glib2-tools - update to 2.62.6-150200.3.30.1
libgmodule-2_0-0 - update to 2.62.6-150200.3.30.1
glib2-tools-debuginfo - update to 2.62.6-150200.3.30.1
libglib-2_0-0-debuginfo - update to 2.62.6-150200.3.30.1
libgio-2_0-0-debuginfo - update to 2.62.6-150200.3.30.1
libglib-2_0-0 - update to 2.62.6-150200.3.30.1
glib2-debugsource - update to 2.62.6-150200.3.30.1
libgobject-2_0-0 - update to 2.62.6-150200.3.30.1
libgobject-2_0-0-debuginfo - update to 2.62.6-150200.3.30.1
glib2.0 (Ubuntu package) - addressed in versions 2.64.6-1~ubuntu20.04.9, 2.72.4-0ubuntu2.5, 2.80.0-6ubuntu3.4, 2.82.1-0ubuntu1.1, 2.84.1-1ubuntu0.1
glib2-debugsource - addressed in versions 2.66.8-24, 2.72.2-25, 2.78.3-15
glib2 - addressed in versions 2.66.8-24, 2.72.2-25, 2.78.3-15
glib2-debuginfo - addressed in versions 2.66.8-24, 2.72.2-25, 2.78.3-15
glib2-devel - addressed in versions 2.66.8-24, 2.72.2-25, 2.78.3-15
glib2-help - addressed in versions 2.66.8-24, 2.72.2-25, 2.78.3-15
glib2-devel - addressed in versions 2.68.4-16.0.1, 2.78.3-5
glib2-doc - addressed in versions 2.68.4-16.0.1, 2.78.3-5
glib2-tests - addressed in versions 2.68.4-16.0.1, 2.78.3-5
glib2-static - addressed in versions 2.68.4-16.0.1, 2.78.3-5
glib2 - addressed in versions 2.68.4-16.0.1, 2.78.3-5
glib2-tests - addressed in versions 2.72.2-25, 2.78.3-15
glib2-static - addressed in versions 2.72.2-25, 2.78.3-15
Splunk Operator for Kubernetes Add-on - update to 3.0.0
OpenShift Virtualization - update to 4.12.20
Red Hat OpenShift Container Platform - addressed in versions 4.14.54, 4.14.55, 4.15.56, 4.16.45, 4.17.37, 4.18.21, 4.19.6, 4.19.7
Red Hat Ceph Storage - update to 7.1

External References

Related Security Bulletins