CVE-2025-7039: Red Hat Enterprise Linux 10
Low severity, CVSS 3.7. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Siemens Ruggedcom RST2428P: before V4.0 (fixed in V4.0)
Published 2025-09-03. Last modified 2026-06-17.