CVE-2025-14087

Executive Summary

GLib GVariant parser buffer‑underflow allows a remote attacker to corrupt the heap, potentially causing denial‑of‑service or arbitrary code execution when processing malicious strings.


Authoritative CVE Metadata - CVSS Base Score: 5.6 (MEDIUM) - Published: 2025-12-10T09:15:47.053 - Last Modified: 2026-09-29T01:16:41.453

Original Description: A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings.

"Keep yourself to the sunshine and you cannot see the shadow."

— Helen Keller
Source: NVD