CVE-2025-6052
Publication date 13 June 2025
Last updated 6 January 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corruption.
Read the notes from the security team
Why is this CVE low priority?
This is a low-severity issue
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| glib2.0 | 25.10 questing |
Not affected
|
| 24.04 LTS noble |
Fixed 2.80.0-6ubuntu3.6
|
|
| 22.04 LTS jammy |
Not affected
|
|
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
Notes
Severity score breakdown
CVSS version: CVSS v3.0
Base score
3.7 · Low
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
References
Related Ubuntu Security Notices (USN)
- USN-7942-1
- GLib vulnerabilities
- 6 January 2026