CVE-2025-4373

EUVD-2025-13592
A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite.
Buffer Underflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
SiemensRUGGEDCOM RST2428P
𝑥
< V3.3
ADP
SiemensSCALANCE XC-300\/XR-300\/XC-400\/XR-500WG\/XR-500 family
𝑥
< V3.3
ADP
SiemensSCALANCE XCH328
𝑥
< V3.3
ADP
SiemensSCALANCE XCM324
𝑥
< V3.3
ADP
SiemensSCALANCE XCM328
𝑥
< V3.3
ADP
SiemensSCALANCE XCM332
𝑥
< V3.3
ADP
SiemensSCALANCE XRH334 \(24 V DC\, 8xFO\, CC\)
𝑥
< V3.3
ADP
SiemensSCALANCE XRM334 \(230 V AC\, 12xFO\)
𝑥
< V3.3
ADP
SiemensSCALANCE XRM334 \(230 V AC\, 8xFO\)
𝑥
< V3.3
ADP
SiemensSCALANCE XRM334 \(230V AC\, 2x10G\, 24xSFP\, 8xSFP\+\)
𝑥
< V3.3
ADP
SiemensSCALANCE XRM334 \(24 V DC\, 12xFO\)
𝑥
< V3.3
ADP
SiemensSCALANCE XRM334 \(24 V DC\, 8xFO\)
𝑥
< V3.3
ADP
SiemensSCALANCE XRM334 \(24V DC\, 2x10G\, 24xSFP\, 8xSFP\+\)
𝑥
< V3.3
ADP
SiemensSCALANCE XRM334 \(2x230 V AC\, 12xFO\)
𝑥
< V3.3
ADP
SiemensSCALANCE XRM334 \(2x230 V AC\, 8xFO\)
𝑥
< V3.3
ADP
SiemensSCALANCE XRM334 \(2x230V AC\, 2x10G\, 24xSFP\, 8xSFP\+\)
𝑥
< V3.3
ADP
SiemensSIMATIC S7-1500 CPU 1518-4 PN\/DP MFP
V3.1.5 ≤
𝑥
< *
ADP
SiemensSIMATIC S7-1500 CPU 1518-4 PN\/DP MFP
V3.1.5 ≤
𝑥
< *
ADP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN\/DP MFP
V3.1.5 ≤
𝑥
< *
ADP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN\/DP MFP
V3.1.5 ≤
𝑥
< *
ADP
SiemensSIPLUS S7-1500 CPU 1518-4 PN\/DP MFP
V3.1.5 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
glib2.0
bookworm
2.74.6-2+deb12u9
fixed
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
2.66.8-1+deb11u8
fixed
forky
2.88.1-2
fixed
sid
2.88.1-2
fixed
trixie
2.84.4-3~deb13u3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
glib2.0
bionic
needs-triage
focal
Fixed 2.64.6-1~ubuntu20.04.9
released
jammy
Fixed 2.72.4-0ubuntu2.5
released
noble
Fixed 2.80.0-6ubuntu3.4
released
oracular
Fixed 2.82.1-0ubuntu1.1
released
plucky
Fixed 2.84.1-1ubuntu0.1
released
questing
not-affected
resolute
not-affected
trusty
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
glib2-devel
suse enterprise desktop 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise desktop 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise server 15 SP4
2.70.5-150400.3.23.1
fixed
suse enterprise server 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise server 15 SP7
2.78.6-150600.4.16.1
fixed
glib2-lang
suse enterprise desktop 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise desktop 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise server 12 SP3
2.48.2-12.46.1
fixed
suse enterprise server 15 SP4
2.70.5-150400.3.23.1
fixed
suse enterprise server 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise server 15 SP7
2.78.6-150600.4.16.1
fixed
glib2-tools
suse enterprise desktop 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise desktop 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise server 12 SP3
2.48.2-12.46.1
fixed
suse enterprise server 15 SP4
2.70.5-150400.3.23.1
fixed
suse enterprise server 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise server 15 SP7
2.78.6-150600.4.16.1
fixed
libgio-2_0-0
suse enterprise desktop 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise desktop 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise server 12 SP3
2.48.2-12.46.1
fixed
suse enterprise server 15 SP4
2.70.5-150400.3.23.1
fixed
suse enterprise server 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise server 15 SP7
2.78.6-150600.4.16.1
fixed
libgio-2_0-0-32bit
suse enterprise desktop 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise desktop 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise server 12 SP3
2.48.2-12.46.1
fixed
suse enterprise server 15 SP4
2.70.5-150400.3.23.1
fixed
suse enterprise server 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise server 15 SP7
2.78.6-150600.4.16.1
fixed
libglib-2_0-0
suse enterprise desktop 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise desktop 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise server 12 SP3
2.48.2-12.46.1
fixed
suse enterprise server 15 SP4
2.70.5-150400.3.23.1
fixed
suse enterprise server 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise server 15 SP7
2.78.6-150600.4.16.1
fixed
libglib-2_0-0-32bit
suse enterprise desktop 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise desktop 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise server 12 SP3
2.48.2-12.46.1
fixed
suse enterprise server 15 SP4
2.70.5-150400.3.23.1
fixed
suse enterprise server 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise server 15 SP7
2.78.6-150600.4.16.1
fixed
libgmodule-2_0-0
suse enterprise desktop 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise desktop 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise server 12 SP3
2.48.2-12.46.1
fixed
suse enterprise server 15 SP4
2.70.5-150400.3.23.1
fixed
suse enterprise server 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise server 15 SP7
2.78.6-150600.4.16.1
fixed
libgmodule-2_0-0-32bit
suse enterprise desktop 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise desktop 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise server 12 SP3
2.48.2-12.46.1
fixed
suse enterprise server 15 SP4
2.70.5-150400.3.23.1
fixed
suse enterprise server 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise server 15 SP7
2.78.6-150600.4.16.1
fixed
libgobject-2_0-0
suse enterprise desktop 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise desktop 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise server 12 SP3
2.48.2-12.46.1
fixed
suse enterprise server 15 SP4
2.70.5-150400.3.23.1
fixed
suse enterprise server 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise server 15 SP7
2.78.6-150600.4.16.1
fixed
libgobject-2_0-0-32bit
suse enterprise desktop 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise desktop 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise server 12 SP3
2.48.2-12.46.1
fixed
suse enterprise server 15 SP4
2.70.5-150400.3.23.1
fixed
suse enterprise server 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise server 15 SP7
2.78.6-150600.4.16.1
fixed
libgthread-2_0-0
suse enterprise desktop 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise desktop 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise sap 15 SP7
2.78.6-150600.4.16.1
fixed
suse enterprise server 12 SP3
2.48.2-12.46.1
fixed
suse enterprise server 15 SP4
2.70.5-150400.3.23.1
fixed
suse enterprise server 15 SP6
2.78.6-150600.4.16.1
fixed
suse enterprise server 15 SP7
2.78.6-150600.4.16.1
fixed
libgthread-2_0-0-32bit
suse enterprise server 12 SP3
2.48.2-12.46.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
glib2
RHEL 8
0:2.56.4-166.el8_10
fixed
RHEL 8.2 AUS
0:2.56.4-8.el8_2.2
fixed
RHEL 8.4 AUS
0:2.56.4-10.el8_4.2
fixed
RHEL 8.6 AUS
0:2.56.4-158.el8_6.2
fixed
RHEL 8.6 E4S
0:2.56.4-158.el8_6.2
fixed
RHEL 8.6 TUS
0:2.56.4-158.el8_6.2
fixed
RHEL 8.8 E4S
0:2.56.4-162.el8_8
fixed
RHEL 8.8 TUS
0:2.56.4-162.el8_8
fixed
RHEL 9
0:2.68.4-16.el9_6.2
fixed
glib2-devel
RHEL 8
0:2.56.4-166.el8_10
fixed
RHEL 8.2 AUS
0:2.56.4-8.el8_2.2
fixed
RHEL 8.4 AUS
0:2.56.4-10.el8_4.2
fixed
RHEL 8.6 AUS
0:2.56.4-158.el8_6.2
fixed
RHEL 8.6 E4S
0:2.56.4-158.el8_6.2
fixed
RHEL 8.6 TUS
0:2.56.4-158.el8_6.2
fixed
RHEL 8.8 E4S
0:2.56.4-162.el8_8
fixed
RHEL 8.8 TUS
0:2.56.4-162.el8_8
fixed
RHEL 9
0:2.68.4-16.el9_6.2
fixed
glib2-doc
RHEL 8
0:2.56.4-166.el8_10
fixed
RHEL 9
0:2.68.4-16.el9_6.2
fixed
glib2-fam
RHEL 8
0:2.56.4-166.el8_10
fixed
RHEL 8.2 AUS
0:2.56.4-8.el8_2.2
fixed
RHEL 8.4 AUS
0:2.56.4-10.el8_4.2
fixed
RHEL 8.6 AUS
0:2.56.4-158.el8_6.2
fixed
RHEL 8.6 E4S
0:2.56.4-158.el8_6.2
fixed
RHEL 8.6 TUS
0:2.56.4-158.el8_6.2
fixed
RHEL 8.8 E4S
0:2.56.4-162.el8_8
fixed
RHEL 8.8 TUS
0:2.56.4-162.el8_8
fixed
glib2-static
RHEL 8
0:2.56.4-166.el8_10
fixed
RHEL 9
0:2.68.4-16.el9_6.2
fixed
glib2-tests
RHEL 8
0:2.56.4-166.el8_10
fixed
RHEL 8.2 AUS
0:2.56.4-8.el8_2.2
fixed
RHEL 8.4 AUS
0:2.56.4-10.el8_4.2
fixed
RHEL 8.6 AUS
0:2.56.4-158.el8_6.2
fixed
RHEL 8.6 E4S
0:2.56.4-158.el8_6.2
fixed
RHEL 8.6 TUS
0:2.56.4-158.el8_6.2
fixed
RHEL 8.8 E4S
0:2.56.4-162.el8_8
fixed
RHEL 8.8 TUS
0:2.56.4-162.el8_8
fixed
RHEL 9
0:2.68.4-16.el9_6.2
fixed