A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fix for CVE-2023-32665. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-32665.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade glib | Mar 21, 2024 | Sep 14, 2023 |
| Amazon Linux Ami 2 | — | Upgrade glib2-docUpgrade glib2Upgrade glib2-testsUpgrade glib2-staticUpgrade glib2-develUpgrade glib2-famUpgrade glib2-debuginfo | Feb 26, 2025 | Sep 14, 2023 |
| Azul Zulu | — | Upgrade Azul Zulu to the latest version | Apr 19, 2024 | Sep 14, 2023 |
| Huawei Euleros 2_0_sp9 | — | Upgrade glib2 | Aug 9, 2023 | Aug 8, 2023 |
| Suse | — | Upgrade libglib-2_0-0Upgrade glib2-develUpgrade libgobject-2_0-0Upgrade libgio-2_0-0Upgrade libgio-2_0-0-32bitUpgrade glib2-langUpgrade libgobject-2_0-0-32bitUpgrade libglib-2_0-0-32bitUpgrade glib2-toolsUpgrade libgmodule-2_0-0Upgrade libgthread-2_0-0Upgrade libgmodule-2_0-0-32bit | Sep 6, 2023 | Sep 5, 2023 |
| Ubuntu | — | Upgrade libglib2.0-bin (Ubuntu Pro)Upgrade libglib2.0-0Upgrade libglib2.0-0 (Ubuntu Pro)Upgrade libglib2.0-bin | Jun 15, 2023 | Jun 14, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Sep 14, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub