glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location.
Metrics
Affected Vendors & Products
References
History
Fri, 26 Sep 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Thu, 25 Sep 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 25 Sep 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location. | |
Title | Glib-networking: uninitialized memory dereferences on glib-networking through glib-networking/tls/openssl/gtlsbio.c via g_tls_bio_new_from_iostream() and g_tls_bio_new_from_datagram_based() | |
First Time appeared |
Redhat
Redhat enterprise Linux |
|
Weaknesses | CWE-476 | |
CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
Vendors & Products |
Redhat
Redhat enterprise Linux |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published: 2025-09-25T15:53:02.569Z
Updated: 2025-09-25T16:33:34.069Z
Reserved: 2025-09-24T12:21:36.721Z
Link: CVE-2025-60019

Updated: 2025-09-25T16:33:31.002Z

Status : Awaiting Analysis
Published: 2025-09-25T16:15:36.357
Modified: 2025-09-26T14:32:19.853
Link: CVE-2025-60019
