LiveActive security incident?Get immediate response
CVE Record

CVE-2025-13601: Glib: integer overflow in in g_escape_uri_string()

A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.

HighCVSS 7.7Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2025-13601 is a memory corruption flaw in GLib, a common Linux system library. A specially large string needing URI escaping can cause an integer overflow and heap buffer overflow. Red Hat rates it high because successful exploitation could corrupt data or crash affected software. No source provided indicates active exploitation.

Executive priority

Treat as a high-priority platform library update, especially on multi-user Linux systems and shared application hosts. It is not currently supported by the provided sources as internet-exploited or actively exploited, so prioritize through normal emergency patch governance rather than incident response escalation.

Technical view

The flaw is in GLib's g_escape_uri_string(). Incorrect escaped-length calculation can overflow when input contains many unacceptable characters, causing writes past a newly allocated heap buffer. The CVSS v3.1 score is 7.7, with local attack vector, low complexity, no privileges, and high integrity and availability impact.

Likely exposure

Exposure is most relevant on listed Red Hat Enterprise Linux systems with affected glib2 or mingw-glib2 packages. Risk depends on whether local users or processes can drive applications into calling g_escape_uri_string() with extremely large attacker-controlled input.

Exploitation context

The provided CVSS vector is local, not network. The source bundle does not show CISA KEV listing or other evidence of active exploitation. Practical impact likely depends on the consuming application, input path, memory protections, and whether the overflow is reachable in normal workflows.

Researcher notes

Key unknowns are application reachability and exploitability beyond corruption or denial of service. The bug requires extremely large inputs with many escapable characters. Validate affected package versions from vendor advisories and avoid assuming exposure unless a local or application-mediated input path reaches g_escape_uri_string().

Mitigation direction

  • Apply the applicable Red Hat RHSA update for each affected RHEL stream.
  • Prioritize systems where untrusted local users or workloads can influence URI escaping inputs.
  • Track GLib package guidance from Red Hat or your Linux distribution vendor.
  • Include bundled or statically linked GLib copies in software inventory review.

Validation and detection

  • Inventory glib2 and mingw-glib2 package versions across affected RHEL versions.
  • Map each host to the relevant Red Hat advisory and package stream.
  • Confirm updated packages are installed after maintenance.
  • Review application inventories for software using GLib URI escaping paths.
Prepared
Confidence
high
Sources
12

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-190: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Container behavior lookup

The affected technology mentions containers, so container-specific ATT&CK technique review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2025-13601 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.7 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
5Timeline events
2ADP providers
34Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.7CVSS 3.1HighCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H2.55.2redhat

Vulnerability scoring details

Base CVSS 3.1 score

7.7High
CVSS 3.1 vector shape for CVE-2025-13601Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. Source timelineredhat

    Reported to Red Hat.

  2. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  3. Source timelineredhat

    Made public.

  4. CVE publishedCVE Program

    The CVE record was published.

  5. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
siemens-SADPADP container

Source materials

  • CVE List V5 sourceCVE List V5
  • RHSA-2026:0936CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:0975CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:0991CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:1323CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:1324CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:1326CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:1327CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:1465CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:1608CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:1624CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:1625CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:1626CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:1627CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:1652CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:1736CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:18344CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:18705CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:2064CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:2072CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:2485CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:2563CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:2633CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
  • RHSA-2026:2659CVE reference, redhat · vendor-advisory, x_refsource_REDHAT
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Unknown vendorglibglib, 0unaffected
Red HatRed Hat Enterprise Linux 10glib2, 0:2.80.4-10.el10_1.12affected
Red HatRed Hat Enterprise Linux 10mingw-glib2, 0:2.87.0-1.el10affected
Red HatRed Hat Enterprise Linux 10.0 Extended Update Supportglib2, 0:2.80.4-4.el10_0.8affected
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Supportglib2, 0:2.56.1-11.el7_9affected
Red HatRed Hat Enterprise Linux 8glib2, 0:2.56.4-168.el8_10affected
Red HatRed Hat Enterprise Linux 8.2 Advanced Update Supportglib2, 0:2.56.4-8.el8_2.4affected
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportglib2, 0:2.56.4-10.el8_4.4affected
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onglib2, 0:2.56.4-10.el8_4.4affected
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportglib2, 0:2.56.4-158.el8_6.4affected
Red HatRed Hat Enterprise Linux 8.6 Telecommunications Update Serviceglib2, 0:2.56.4-158.el8_6.4affected
Red HatRed Hat Enterprise Linux 8.6 Update Services for SAP Solutionsglib2, 0:2.56.4-158.el8_6.4affected
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Serviceglib2, 0:2.56.4-164.el8_8affected
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutionsglib2, 0:2.56.4-164.el8_8affected
Red HatRed Hat Enterprise Linux 9glib2, 0:2.68.4-18.el9_7.1affected
Red HatRed Hat Enterprise Linux 9mingw-glib2, 0:2.78.6-3.el9affected
Red HatRed Hat Enterprise Linux 9glib2, 0:2.68.4-18.el9_7.1affected
Red HatRed Hat Enterprise Linux 9.0 Update Services for SAP Solutionsglib2, 0:2.68.4-5.el9_0.4affected
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutionsglib2, 0:2.68.4-7.el9_2.4affected
Red HatRed Hat Enterprise Linux 9.4 Extended Update Supportglib2, 0:2.68.4-14.el9_4.5affected
Red HatRed Hat Enterprise Linux 9.6 Extended Update Supportglib2, 0:2.68.4-16.el9_6.4affected
Red HatRed Hat OpenShift Container Platform 4.12rhcos, 412.86.202602021310-0affected
Red HatRed Hat OpenShift Container Platform 4.13rhcos, 413.92.202602240113-0affected
Red HatRed Hat OpenShift Container Platform 4.14rhcos, 414.92.202602171627-0affected
Red HatRed Hat OpenShift Container Platform 4.15rhcos, 415.92.202603101737-0affected
Red HatRed Hat OpenShift Container Platform 4.16rhcos, 416.94.202602101357-0affected
Red HatRed Hat OpenShift Container Platform 4.17rhcos, 417.94.202602090846-0affected
Red HatRed Hat OpenShift Container Platform 4.18rhcos, 418.94.202602022246-0affected
Red HatRed Hat OpenShift Container Platform 4.19rhcos, 4.19.9.6.202602112047-0affected
Red HatRed Hat Ceph Storage 8rhceph/rhceph-8-rhel9, 1769512383affected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-190 · source CWE mapping

Integer Overflow or Wraparound

Integer Overflow or Wraparound represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.