{"schema_version":"1.7.2","id":"OESA-2026-1142","modified":"2026-08-06T11:10:11Z","published":"2026-01-16T11:10:11Z","upstream":["CVE-2025-13601"],"summary":"glib2 security update","details":"GLib is a bundle of three (formerly five) low-level system libraries written in C and developed mainly by GNOME. GLib&amp;apos;s code was separated from GTK, so it can be used by software other than GNOME and has been developed in parallel ever since.\r\n\r\nSecurity Fix(es):\n\nA heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.(CVE-2025-13601)","affected":[{"package":{"ecosystem":"openEuler:20.03-LTS-SP4","name":"glib2","purl":"pkg:rpm/openEuler/glib2&distro=openEuler-20.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.66.8-22.oe2003sp4"}]}],"ecosystem_specific":{"aarch64":["glib2-2.66.8-22.oe2003sp4.aarch64.rpm","glib2-debuginfo-2.66.8-22.oe2003sp4.aarch64.rpm","glib2-debugsource-2.66.8-22.oe2003sp4.aarch64.rpm","glib2-devel-2.66.8-22.oe2003sp4.aarch64.rpm"],"noarch":["glib2-help-2.66.8-22.oe2003sp4.noarch.rpm"],"src":["glib2-2.66.8-22.oe2003sp4.src.rpm"],"x86_64":["glib2-2.66.8-22.oe2003sp4.x86_64.rpm","glib2-debuginfo-2.66.8-22.oe2003sp4.x86_64.rpm","glib2-debugsource-2.66.8-22.oe2003sp4.x86_64.rpm","glib2-devel-2.66.8-22.oe2003sp4.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-1142"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-13601"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"}],"database_specific":{"severity":"High"}}
