CVE-2025-13601High· 7.7▾ TwilightA heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would ne…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
0.3% → 0.3%
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.
codeready_linux_builder = 9.0codeready_linux_builder_for_ibm_z_systems = 9.0_s390xcodeready_linux_builder_for_power_little_endian = 9.0_ppc64lecodeready_linux_builder_for_x86_64 = 9.0enterprise_linux_for_arm_64 = 9.0enterprise_linux_for_ibm_z_systems = 9.0_s390xenterprise_linux_for_power_little_endian = 9.0_ppc64leenterprise_linux_for_x86_64 = 9.0codeready_linux_builder_for_arm64 = 10.0codeready_linux_builder_for_ibm_z_systems = 10.0_s390xcodeready_linux_builder_for_power_little_endian = 10.0_ppc64lecodeready_linux_builder_for_x86_64 = 10.0enterprise_linux_for_arm_64 = 10.0enterprise_linux_for_ibm_z_systems = 10.0_s390xenterprise_linux_for_power_little_endian = 10.0_ppc64leenterprise_linux_for_x86_64 = 10.0codeready_linux_builder_for_arm64 = 8.0codeready_linux_builder_for_ibm_z_systems = 8.0_s390xcodeready_linux_builder_for_power_little_endian = 8.0_ppc64lecodeready_linux_builder_for_x86_64 = 8.0enterprise_linux_for_arm_64 = 8.0enterprise_linux_for_ibm_z_systems = 8.0_s390xenterprise_linux_for_power_little_endian = 8.0_ppc64leenterprise_linux_for_x86_64 = 8.0enterprise_linux_for_arm_64 = 9.2enterprise_linux_for_ibm_z_systems = 9.2_s390xenterprise_linux_for_power_little_endian = 9.2_ppc64leenterprise_linux_for_x86_64 = 9.2enterprise_linux_server_aus = 9.2codeready_linux_builder_for_arm64_eus = 9.4codeready_linux_builder_for_ibm_z_systems = 9.4_s390xcodeready_linux_builder_for_power_little_endian = 9.4_ppc64lecodeready_linux_builder_for_x86_64 = 9.4enterprise_linux_for_arm_64 = 9.4enterprise_linux_for_ibm_z_systems = 9.4_s390xenterprise_linux_for_power_little_endian = 9.4_ppc64leenterprise_linux_for_x86_64 = 9.4enterprise_linux_for_x86_64_eus = 9.4enterprise_linux_server_aus = 9.4enterprise_linux_server_for_power_little_endian = 9.4_ppc64leenterprise_linux_server_for_power_little_endian_eus = 9.4_ppc64lecodeready_linux_builder_for_arm64_eus = 10.0codeready_linux_builder_for_ibm_z_systems_eus = 10.0_s390xcodeready_linux_builder_for_power_little_endian_eus = 10.0_ppc64lecodeready_linux_builder_for_x86_64_eus = 10.0enterprise_linux_for_arm_64_eus = 10.0enterprise_linux_for_ibm_z_systems_eus = 10.0_s390xenterprise_linux_for_power_little_endian_eus = 10.0_ppc64leenterprise_linux_for_x86_64_eus = 10.0enterprise_linux_server_for_power_little_endian = 10.0_ppc64lecodeready_linux_builder_for_arm64 = 9.6codeready_linux_builder_for_ibm_z_systems = 9.6_s390xcodeready_linux_builder_for_power_little_endian = 9.6_ppc64lecodeready_linux_builder_for_x86_64 = 9.6enterprise_linux_for_arm_64 = 9.6enterprise_linux_for_ibm_z_systems = 9.6_s390xenterprise_linux_for_power_little_endian = 9.6_ppc64leenterprise_linux_for_power_little_endian_eus = 9.6_ppc64leenterprise_linux_for_x86_64 = 9.6enterprise_linux_for_x86_64_eus = 9.6enterprise_linux_server_aus = 9.6enterprise_linux_server_for_power_little_endian = 9.6_ppc64leenterprise_linux_for_x86_64 = 8.6enterprise_linux_for_x86_64_eus = 8.6enterprise_linux_server_aus = 8.6enterprise_linux_server_for_power_little_endian = 8.6_ppc64leenterprise_linux_server_tus = 8.6enterprise_linux_for_x86_64 = 8.8enterprise_linux_for_x86_64_eus = 8.8enterprise_linux_server_for_power_little_endian = 8.8_ppc64leenterprise_linux_server_tus = 8.8enterprise_linux_for_x86_64_eus = 8.4enterprise_linux_server_aus = 8.4enterprise_linux_server_aus = 8.2ceph_storage = 8.0discovery = 2.0glib < 2.86.3openshift_container_platform = 4.12openshift_container_platform = 4.16openshift_container_platform = 4.17openshift_container_platform = 4.18openshift_container_platform = 4.19openshift_container_platform_for_arm64 = 4.12openshift_container_platform_for_arm64 = 4.16openshift_container_platform_for_arm64 = 4.17openshift_container_platform_for_arm64 = 4.18openshift_container_platform_for_arm64 = 4.19openshift_container_platform_for_ibm_z = 4.12openshift_container_platform_for_ibm_z = 4.16openshift_container_platform_for_ibm_z = 4.17openshift_container_platform_for_ibm_z = 4.18openshift_container_platform_for_ibm_z = 4.19openshift_container_platform_for_linuxone = 4.12openshift_container_platform_for_linuxone = 4.16openshift_container_platform_for_linuxone = 4.17openshift_container_platform_for_linuxone = 4.18openshift_container_platform_for_linuxone = 4.19openshift_container_platform_for_power = 4.12openshift_container_platform_for_power = 4.16openshift_container_platform_for_power = 4.17Upgrade past the affected range:
glib 2.86.3Connected by shared product, vendor, weakness, or advisory.
CVE-2023-40548High· 7.4A buffer overflow was found in Shim in the 32-bit system
CVE-2022-0330High· 7.8A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU
CVE-2025-6170Low· 2.5A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files
CVE-2026-2921High· 7.8GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability
CVE-2026-10649High· 8.6A flaw was found in Pacemaker
CVE-2024-22051Critical· 9.8CommonMarker versions prior to 0.23.4 are at risk of an integer overflow vulnerability