A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade glib2.0 | Sep 8, 2025 | Sep 8, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade glib2 | Jan 15, 2026 | Jan 13, 2026 |
| Huawei Euleros 2_0_sp11 | — | Upgrade glib2 | Dec 12, 2025 | Nov 11, 2025 |
| Huawei Euleros 2_0_sp12 | — | Upgrade glib2 | Nov 12, 2025 | Nov 11, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade glib2 | Nov 21, 2025 | Nov 11, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jul 2, 2025 |
| Ubuntu | — | Upgrade libglib2.0-0Upgrade libglib2.0-0t64Upgrade libglib2.0-bin | Jan 7, 2026 | Sep 3, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub