JLSEC-2025-157
Dashboard / Vulnerabilities / JLSEC-2025-157
Summary: An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3
Details: An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function `g_bytes_new` has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption.
References: https://gitlab.gnome.org/GNOME/glib/-/issues/2319, https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E, https://lists.debian.org/debian-lts-announce/2022/06/msg00006.html, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2REA7RVKN7ZHRLJOEGBRQKJIPZQPAELZ/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JJMPNDO4GDVURYQFYKFOWY5HAF4FTEPN/, https://security.gentoo.org/glsa/202107-13, https://security.netapp.com/advisory/ntap-20210319-0004/
Affected packages
Package
Name: Glib_jll
Purl: pkg:julia/Glib_jll?uuid=7746bdde-850d-59dc-9ae8-88ece973131d
Affected ranges
Type: SEMVER
Events:
