CVE Vulnerabilities

CVE-2025-4373

Buffer Underwrite ('Buffer Underflow')

Published: May 06, 2025 | Modified: May 12, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
4.8 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite.

Weakness

The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatglib2-0:2.80.4-4.el10_0.6*
Red Hat Enterprise Linux 8RedHatglib2-0:2.56.4-166.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatglib2-0:2.56.4-8.el8_2.2*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatglib2-0:2.56.4-10.el8_4.2*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatglib2-0:2.56.4-10.el8_4.2*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatglib2-0:2.56.4-158.el8_6.2*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatglib2-0:2.56.4-158.el8_6.2*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatglib2-0:2.56.4-158.el8_6.2*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatglib2-0:2.56.4-162.el8_8*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatglib2-0:2.56.4-162.el8_8*
Red Hat Enterprise Linux 9RedHatglib2-0:2.68.4-16.el9_6.2*
Red Hat Enterprise Linux 9RedHatglib2-0:2.68.4-16.el9_6.2*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatglib2-0:2.68.4-5.el9_0.2*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatglib2-0:2.68.4-7.el9_2.2*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatglib2-0:2.68.4-14.el9_4.3*
Red Hat Insights proxy 1.5RedHatinsights-proxy/insights-proxy-container-rhel9:1.5.5-1754504343*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/jaeger-agent-rhel8:rhosdt-3.6-1753265330*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/jaeger-all-in-one-rhel8:rhosdt-3.6-1753265394*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/jaeger-collector-rhel8:rhosdt-3.6-1753265332*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/jaeger-es-index-cleaner-rhel8:rhosdt-3.6-1753265435*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/jaeger-es-rollover-rhel8:rhosdt-3.6-1753265342*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/jaeger-ingester-rhel8:rhosdt-3.6-1753265332*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/jaeger-operator-bundle:rhosdt-3.6-1753269432*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/jaeger-query-rhel8:rhosdt-3.6-1753265411*
Red Hat OpenShift distributed tracing 3.6.0RedHatrhosdt/jaeger-rhel8-operator:rhosdt-3.6-1753265314*
Glib2.0Ubuntuesm-infra/focal*
Glib2.0Ubuntuesm-infra/xenial*
Glib2.0Ubuntufocal*
Glib2.0Ubuntujammy*
Glib2.0Ubuntunoble*
Glib2.0Ubuntuoracular*
Glib2.0Ubuntuplucky*
Glib2.0Ubuntuupstream*

Potential Mitigations

References