A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.
Security readout for executives and security teams
Plain-English summary
A malicious file or remote-filesystem attribute can trigger a memory overflow in GLib's input/output handling. An affected application may crash, interrupting service. The supplied evidence supports denial of service, not data theft, modification, or code execution.
Executive priority
Schedule prompt remediation through normal vulnerability-management processes, prioritizing systems that process untrusted files or remote filesystem metadata and services where crashes have material operational impact. Emergency treatment is not supported by the supplied evidence because severity is medium and active exploitation is not reported.
Technical view
An integer overflow in GIO's escape_byte_string() can produce an undersized allocation before attribute data is escaped, causing a heap buffer overflow. CVSS 3.1 is 6.5: network-reachable, low complexity, no privileges, user interaction required, unchanged scope, and availability impact only.
Likely exposure
Confirmed exposure includes the listed glib2 builds across supported and extended-support RHEL 8, 9, and 10 variants. Practical risk exists where applications process attacker-controlled file or remote-filesystem attributes through GIO. The supplied GNOME entry does not identify an affected upstream version and marks its default status unaffected.
Exploitation context
The bundle does not report active exploitation, and the CVE is not listed as KEV. Exploitation requires user interaction according to the CVSS vector. Evidence supports application crashes or denial of service; it does not establish code execution.
Researcher notes
The affected path is GIO attribute escaping in escape_byte_string(). The security consequence is heap corruption caused by integer-overflow-driven allocation miscalculation. The available assessment scores confidentiality and integrity impacts as none and availability as high. The bundle provides no proof of reliable code execution or affected upstream GLib version range.
Mitigation direction
Identify systems running the affected RHEL glib2 package builds listed in the CVE record.
Review the Red Hat advisory applicable to each RHEL release and support channel.
Apply vendor-provided corrected packages where prescribed by the applicable advisory.
Reduce processing of untrusted remote-filesystem attributes until remediation is confirmed.
Validation and detection
Compare installed glib2 versions and RHEL channels against the affected entries.
Confirm each system received the correction specified by its applicable Red Hat advisory.
Restart affected applications or systems if vendor guidance requires it.
Verify applications safely handle untrusted file and remote-filesystem attributes without crashing.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-190: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The affected technology mentions containers, so container-specific ATT&CK technique review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.