Bug 2398140 (CVE-2025-60019) - CVE-2025-60019 glib-networking: Uninitialized Memory Dereferences on glib-networking through glib-networking/tls/openssl/gtlsbio.c via g_tls_bio_new_from_iostream() and g_tls_bio_new_from_datagram_based()
Summary: CVE-2025-60019 glib-networking: Uninitialized Memory Dereferences on glib-net...
Keywords:
Status: NEW
Alias: CVE-2025-60019
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-09-25 13:01 UTC by OSIDB Bzimport
Modified: 2025-09-25 15:01 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-09-25 13:01:29 UTC
glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location. (Because the OpenSSL backend is not built by default, this bug will not affect most Linux distributions.)


Note You need to log in before you can comment on or make changes to this bug.