All errata/sisyphus_riscv64/ALT-PU-2025-10285-1
ALT-PU-2025-10285-1

Package update glib2 in branch sisyphus_riscv64

Version2.84.4-alt1
Task#0
Published2025-08-11
Max severityLOW
Severity:

Closed issues (1)

CVE-2025-7039
LOW3.7

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.

Published: 2025-09-03Modified: 2026-04-15
CVSS 3.xLOW 3.7
CVSS:3.x/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N