A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fix for CVE-2023-32665. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-32665.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade glib | Mar 21, 2024 | Sep 14, 2023 |
| Amazon Linux Ami 2 | — | Upgrade glib2Upgrade glib2-testsUpgrade glib2-docUpgrade glib2-debuginfoUpgrade glib2-staticUpgrade glib2-develUpgrade glib2-fam | Feb 26, 2025 | Sep 14, 2023 |
| Azul Zulu | — | Upgrade Azul Zulu to the latest version | Apr 19, 2024 | Sep 14, 2023 |
| Huawei Euleros 2_0_sp9 | — | Upgrade glib2 | Aug 9, 2023 | Aug 8, 2023 |
| Suse | — | Upgrade libgio-2_0-0-32bitUpgrade libgio-2_0-0Upgrade libgobject-2_0-0Upgrade libglib-2_0-0Upgrade glib2-develUpgrade glib2-langUpgrade libgmodule-2_0-0-32bitUpgrade libgobject-2_0-0-32bitUpgrade libglib-2_0-0-32bitUpgrade libgmodule-2_0-0Upgrade glib2-toolsUpgrade libgthread-2_0-0 | Sep 6, 2023 | Sep 5, 2023 |
| Ubuntu | — | Upgrade libglib2.0-bin (Ubuntu Pro)Upgrade libglib2.0-0Upgrade libglib2.0-0 (Ubuntu Pro)Upgrade libglib2.0-bin | Jun 15, 2023 | Jun 14, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Sep 14, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub