CVE-2025-13601
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the gescapeuri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://access.redhat.com/errata/RHSA-2026:0936, https://access.redhat.com/errata/RHSA-2026:0975, https://access.redhat.com/errata/RHSA-2026:0991, https://access.redhat.com/errata/RHSA-2026:1323, https://access.redhat.com/errata/RHSA-2026:1324, https://access.redhat.com/errata/RHSA-2026:1326, https://access.redhat.com/errata/RHSA-2026:1327, https://access.redhat.com/errata/RHSA-2026:1465, https://access.redhat.com/errata/RHSA-2026:1608, https://access.redhat.com/errata/RHSA-2026:1624, https://access.redhat.com/errata/RHSA-2026:1625, https://access.redhat.com/errata/RHSA-2026:1626, https://access.redhat.com/errata/RHSA-2026:1627, https://access.redhat.com/errata/RHSA-2026:1652, https://access.redhat.com/errata/RHSA-2026:1736, https://access.redhat.com/errata/RHSA-2026:2064, https://access.redhat.com/errata/RHSA-2026:2072, https://access.redhat.com/errata/RHSA-2026:2485, https://access.redhat.com/errata/RHSA-2026:2563, https://access.redhat.com/errata/RHSA-2026:2633, https://access.redhat.com/errata/RHSA-2026:2659, https://access.redhat.com/errata/RHSA-2026:2671, https://access.redhat.com/security/cve/CVE-2025-13601, https://bugzilla.redhat.com/showbug.cgi?id=2416741, https://gitlab.gnome.org/GNOME/glib/-/mergerequests/4914, https://bugzilla.redhat.com/show_bug.cgi?id=2416741, https://gitlab.gnome.org/GNOME/glib/-/issues/3827, https://gitlab.gnome.org/GNOME/glib/-/issues/3827
