Integer Overflow Flaw in GLib Affects Vulnerable Software Components
CVE-2025-4373
4.8MEDIUM
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 6 May 2025
What is CVE-2025-4373?
A critical flaw exists in the GLib library that creates an integer overflow condition in the g_string_insert_unichar() function. When an unusually large index is specified for character insertion, the function may cause the position value to wrap around, resulting in a buffer underwrite. This vulnerability could be exploited by attackers to overwrite memory locations, potentially leading to application crashes or enabling arbitrary code execution. Affected applications utilizing the vulnerable GLib functions should be updated to mitigate risks associated with this security issue.
Affected Version(s)
Red Hat Enterprise Linux 10 0:2.80.4-4.el10_0.6
Red Hat Enterprise Linux 8 0:2.56.4-166.el8_10
Red Hat Enterprise Linux 9 0:2.68.4-16.el9_6.2