Skip to content

CVE-2025-13601 on CTRL-OS 24.05

Packages: glib

Status: New

CVE Information

A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.

Updates

2026-04-07 18:14 CEST

Metadata changes:

  • Status for package glib: “New