CVE-2025-7039: Red Hat Enterprise Linux 10

Low severity, CVSS 3.7. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.

Affected products

  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Siemens Ruggedcom RST2428P: before V4.0 (fixed in V4.0)

Published 2025-09-03. Last modified 2026-06-17.