Junglewise Threat Intelligence

CVE-2025-4056: GNOME GLib integer overflow in gspawn-win32.c

CVE-2025-4056 · Severity: high · CVSS 7.5 · Published 2025-07-28

Technologies: Gnome Glib, Microsoft Windows. Vendors: Gnome, Microsoft.

Executive brief

GLib is a fundamental software library used by many applications on Windows to handle core system tasks. A flaw in how it processes long command lines can cause applications to crash unexpectedly. This could allow an attacker to disrupt services or cause software to fail by providing specially crafted, extremely long inputs to affected programs.

Technical details

An integer overflow vulnerability exists in the `protect_argv_string` function within `gspawn-win32.c` in GLib. The function uses a signed integer (`gint`) to calculate the length of command line arguments; when an extremely long string is provided, this variable can overflow. This leads to either an undersized memory allocation resulting in a heap-based buffer overflow (segmentation fault) or a negative value being passed to `g_malloc`, triggering an intentional abort. The vulnerability is specific to Windows builds and can be triggered by any application using `g_spawn` functions with untrusted, long input strings. The issue is fixed in GLib version 2.84.1 by using `size_t` for length calculations and adding input validation.

Affected products

  • GNOME GLib < 2.84.1

Timeline

  • 2025-02-25: disclosed: Vulnerability reported via YesWeHack
  • 2025-04-01: patched: Fix merged in version 2.84.1
  • 2025-07-28: advisory: NVD publication date

References

Related threats