CVE-2025-14087: Glib: glib: buffer underflow in gvariant parser leads to heap corruption

Published Dec 5, 2025
·
Updated

A buffer-underflow vulnerability exists in GLib’s GVariant parser, specifically within bytestringparse() and stringparse(). The parser uses signed 32-bit integers (gint) as loop indices (i and j). When extremely large strings are parsed, these counters overflow into negative values, causing the parser to write to memory before the start of the allocated buffer (str[j++]). This results in a classic out-of-bounds write condition. Because GVariant parsing is often performed on attacker-influenced data, a remote attacker can trigger heap corruption, causing a crash or potentially achieving code execution. This flaw has been confirmed by maintainers and patched upstream.

Other sources

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.

MITRE

Glib: glib: buffer underflow in gvariant parser leads to heap corruption

Microsoft

Affected Software

13 affected componentsFixes available
Gnome GLib
Microsoft cbl2 glib 2.71.0-8
Microsoft azl3 glib 2.78.6-5
Microsoft cbl2 glib 2.71.0-9
Gnome GLib<2.86.3
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Enterprise Linux=10.0
IBM CICS Transaction Gateway for Multiplatforms<=9.1
IBM CICS Transaction Gateway for Multiplatforms<=9.2
IBM CICS Transaction Gateway for Multiplatforms<=9.3
IBM CICS Transaction Gateway for Multiplatforms<=10.1

Event History

Dec 5, 2025
Data Sourced
via Red Hat·08:44 AM
DescriptionSeverityAffected Software
Dec 10, 2025
CVE Published
via MITRE·09:01 AM
Data Sourced
via MITRE·09:01 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Dec 13, 2025
Data Sourced
via Microsoft·01:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·01:01 AM
Affected Software
Updated
via Microsoft·01:01 AM
DescriptionSeverity
Jul 29, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-14087?

CVE-2025-14087 is classified as a high severity vulnerability due to its potential for causing denial of service and code execution.

2

How do I fix CVE-2025-14087?

To fix CVE-2025-14087, update GLib to the latest version that addresses the buffer-underflow vulnerability.

3

What types of attacks can CVE-2025-14087 facilitate?

CVE-2025-14087 can facilitate remote attacks that lead to heap corruption, causing denial of service or potential code execution.

4

Which software is affected by CVE-2025-14087?

CVE-2025-14087 specifically affects GLib, commonly used in various applications for handling data types.

5

Is user intervention required to exploit CVE-2025-14087?

Yes, exploitation of CVE-2025-14087 requires that a user processes maliciously crafted input strings.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203