CVE-2025-2722: GNOME libgsf gsf_prop_settings_collect_va heap-based overflow
Rejected reason: REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The code maintainer explains that "[the] call is invalid [because] pnparam is an input-output parameter indicating how big an array has already been allocated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2722?
CVE-2025-2722 has been declared as a critical vulnerability.
What causes CVE-2025-2722?
CVE-2025-2722 is caused by a heap-based buffer overflow due to manipulation of the argument n_alloced_params in the function gsf_prop_settings_collect_va.
Who is affected by CVE-2025-2722?
CVE-2025-2722 affects users of GNOME libgsf versions up to and including 1.14.53.
How do I fix CVE-2025-2722?
To fix CVE-2025-2722, it is recommended to update GNOME libgsf to a version later than 1.14.53.
Do I need local access to exploit CVE-2025-2722?
Yes, local access is required to exploit the CVE-2025-2722 vulnerability.