OESA-2025-2398

    Dashboard / Vulnerabilities / OESA-2025-2398

    OESA-2025-2398

    Published: 11 Oct 2025Last Modified: 18 Aug 2026

    Summary: glib-networking security update

    Details: glib-networking contains the implementations of certain GLib networking features that cannot be implemented directly in GLib itself because of their dependencies. Security Fix(es): glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out of bounds read.(CVE-2025-60018) glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location.(CVE-2025-60019)

    Affected packages

    Package

    Name: glib-networking

    Purl: pkg:rpm/openEuler/glib-networking&distro=openEuler-24.03-LTS-SP1

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.78.0-2.oe2403sp1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    OESA-2025-2398 | CVE-DB