OESA-2025-2399
Dashboard / Vulnerabilities / OESA-2025-2399
OESA-2025-2399
Summary: glib-networking security update
Details: glib-networking contains the implementations of certain GLib networking features that cannot be implemented directly in GLib itself because of their dependencies. Security Fix(es): glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out of bounds read.(CVE-2025-60018) glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location.(CVE-2025-60019)
References: https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2025-2399, https://nvd.nist.gov/vuln/detail/CVE-2025-60018, https://nvd.nist.gov/vuln/detail/CVE-2025-60019
Affected packages
Package
Name: glib-networking
Purl: pkg:rpm/openEuler/glib-networking&distro=openEuler-24.03-LTS-SP2
Affected ranges
Type: ECOSYSTEM
Events:
