Fedora Account System
Red Hat Associate
Red Hat Customer
A buffer-underflow vulnerability exists in GLib’s GVariant parser, specifically within bytestring_parse() and string_parse(). The parser uses signed 32-bit integers (gint) as loop indices (i and j). When extremely large strings are parsed, these counters overflow into negative values, causing the parser to write to memory before the start of the allocated buffer (str[j++]). This results in a classic out-of-bounds write condition. Because GVariant parsing is often performed on attacker-influenced data, a remote attacker can trigger heap corruption, causing a crash or potentially achieving code execution. This flaw has been confirmed by maintainers and patched upstream.
The current state per RHEL's advisory for CVE-2025-14087 is Fix Deferred. Is there an ETA for when this will be patched, particularly as the CVE has been rated by NVD as Critical.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:15953 https://access.redhat.com/errata/RHSA-2026:15953
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:15971 https://access.redhat.com/errata/RHSA-2026:15971
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:15969 https://access.redhat.com/errata/RHSA-2026:15969
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19148 https://access.redhat.com/errata/RHSA-2026:19148
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19361 https://access.redhat.com/errata/RHSA-2026:19361
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:19459 https://access.redhat.com/errata/RHSA-2026:19459
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:19452 https://access.redhat.com/errata/RHSA-2026:19452
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:19460 https://access.redhat.com/errata/RHSA-2026:19460
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:19457 https://access.redhat.com/errata/RHSA-2026:19457
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:19523 https://access.redhat.com/errata/RHSA-2026:19523
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:19524 https://access.redhat.com/errata/RHSA-2026:19524
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:19565 https://access.redhat.com/errata/RHSA-2026:19565
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:19566 https://access.redhat.com/errata/RHSA-2026:19566
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:19567 https://access.redhat.com/errata/RHSA-2026:19567