← Vulnerability feed

Vulnerability record · CVE-2025-13601 · published 26 November 2025

CVE-2025-13601: Redhat codeready linux builder integer overflow vulnerability

Redhat · Codeready Linux Builder

A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.

7.7 CVSS 3.1 High EPSS 0.32% · top 77.3% CWE-190 · Integer overflow
7.7CVSS 3.1 base score
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
29Affected product versions listed by NVD
33References, 1 tagged exploit
31 Aug 2026Last modified by NVD

Description

A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Affected products

29 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://access.redhat.com/errata/RHSA-2026:0936 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:0975 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:0991 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:1323 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:1324 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:1326 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:1327 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:1465 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:1608 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:1624 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:1625 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:1626 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:1627 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:1652 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:1736 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:18344
https://access.redhat.com/errata/RHSA-2026:18705
https://access.redhat.com/errata/RHSA-2026:2064 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:2072 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:2485 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:2563 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:2633 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:2659 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:2671 Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:2974
https://access.redhat.com/errata/RHSA-2026:3415
https://access.redhat.com/errata/RHSA-2026:4419
https://access.redhat.com/errata/RHSA-2026:7461
https://access.redhat.com/security/cve/CVE-2025-13601 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2416741 Issue TrackingVendor Advisory
https://gitlab.gnome.org/GNOME/glib/-/issues/3827 ExploitIssue Tracking
https://gitlab.gnome.org/GNOME/glib/-/merge_requests/4914 Third Party Advisory
https://cert-portal.siemens.com/productcert/html/ssa-253495.html

Track CVE-2025-13601 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-8720WebKit memory corruption allows code execution via crafted web contentWebKit contains multiple memory corruption issues in memory handling that are triggered when processing maliciously crafted web content. Successful e…KEVEPSS 1.6%analysed7.8CVE-2023-4911GNU C Library ld.so GLIBC_TUNABLES heap buffer overflowThe GNU C Library dynamic loader ld.so mishandles the GLIBC_TUNABLES environment variable, causing a heap-based buffer overflow and out-of-bounds wri…KEVEPSS 81%analysed7.8CVE-2022-0847Linux kernel pipe buffer flaw allows local privilege escalationThe flags member of the new pipe buffer structure was not properly initialized in copy_page_to_iter_pipe and push_pipe, so it could hold stale values…KEVEPSS 93%analysed7.8CVE-2022-0492Linux kernel cgroups v1 release_agent privilege escalation and container escapeThe Linux kernel's cgroup_release_agent_write in kernel/cgroup/cgroup-v1.c mishandles authorization, letting the cgroups v1 release_agent feature be …KEVEPSS 5.5%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2025-14087Gnome glib integer overflow vulnerabilityA flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potenti…EPSS 0.83%9.8CVE-2024-52533Gnome glib classic buffer overflow vulnerabilitygio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient f…EPSS 1.3%9.8CVE-2022-26148Grafana Zabbix integration exposes cleartext password in page sourceGrafana through 7.3.4, when integrated with Zabbix, embeds the Zabbix account password and URL in the HTML source of api_jsonrpc.php. Anyone who can …EPSS 53%analysed

Source: NIST National Vulnerability Database (record CVE-2025-13601), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.