CVE-2025-14087: Gnome Glib
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.
Affected products
- Gnome Glib: before 2.86.3 (fixed in 2.86.3)
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only; version 9.0 only; version 10.0 only
Published 2025-12-10. Last modified 2026-10-02.