Junglewise Threat Intelligence

CVE-2025-13601: GNOME GLib heap buffer overflow in g_escape_uri_string

CVE-2025-13601 · Severity: high · CVSS 7.7 · Published 2025-11-26

Technologies: Gnome Glib, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9. Vendors: Gnome, Red Hat.

Executive brief

A security vulnerability has been identified in GLib, a fundamental software library used by many Linux applications and the GNOME desktop environment. The flaw occurs when the library processes specially crafted web addresses (URIs), potentially causing an application to crash or behave unpredictably. This could allow a local attacker to disrupt system operations or interfere with data integrity on affected Linux systems.

Technical details

A heap-based buffer overflow exists in GLib's g_escape_uri_string() function due to an integer overflow during buffer size calculation. When a string containing a high volume of characters requiring escaping is processed, the calculated length for the new buffer can wrap around, resulting in an undersized allocation. Subsequent writing of the escaped string leads to an out-of-bounds write on the heap. This vulnerability can be triggered locally and may result in a denial of service or data corruption. Patches have been released by Red Hat for Enterprise Linux 9 and 10, and upstream fixes are available in the GNOME GLib repository.

Affected products

  • GNOME glib2 through 2.80.4
  • Red Hat Enterprise Linux 9 glib2-2.68.4-18.el9_7.1
  • Red Hat Enterprise Linux 10 glib2-2.80.4-10.el10_1.12

Timeline

  • 2025-11-26: advisory: Initial NVD publication
  • 2026-01-21: patched: Red Hat released updates for RHEL 9
  • 2026-01-22: patched: Red Hat released updates for RHEL 10

References

Related threats