Junglewise Threat Intelligence

CVE-2025-14087: GNOME GLib heap corruption in GVariant parser

CVE-2025-14087 · Severity: medium · CVSS 5.6 · Published 2025-12-10

Technologies: Red Hat Enterprise Linux 7.0, Gnome Glib, Red Hat Enterprise Linux 10.0, Red Hat Enterprise Linux 8.0, Red Hat Enterprise Linux 9.0. Vendors: Red Hat, Gnome.

Executive brief

A vulnerability has been identified in GLib, a fundamental software library used by many Linux applications and the GNOME desktop environment. An attacker could send specially crafted data to an application using this library to cause a system crash or potentially run unauthorized commands. This could lead to service disruptions or unauthorized access to sensitive information on affected systems.

Technical details

A buffer underflow flaw was discovered in the GVariant parser component of GLib (Gnome Lib). The issue is rooted in an integer overflow (CWE-190) that occurs when processing maliciously crafted input strings, leading to heap corruption. A remote attacker can exploit this by providing specially formatted GVariant data to an application that parses it without sufficient validation. Successful exploitation can result in a denial of service (application crash) or potentially arbitrary code execution. Patches have been released by Red Hat for various Enterprise Linux versions, and the issue is addressed in GLib upstream versions 2.86.3 and later.

Affected products

  • GNOME GLib < 2.86.3
  • Red Hat Enterprise Linux 7.0
  • Red Hat Enterprise Linux 8.0
  • Red Hat Enterprise Linux 9.0
  • Red Hat Enterprise Linux 10.0

Timeline

  • 2025-12-10: disclosed: Initial disclosure by Red Hat
  • 2025-12-10: advisory: NVD publication date
  • 2026-05-11: patched: Red Hat released security updates (RHSA-2026:15953, RHSA-2026:15969, RHSA-2026:15971)

References

Related threats