CVE-2025-4373
Executive Summary
CVE-2025-4373 exposes an integer overflow in GLib’s g_string_insert_unichar() when inserting at a large position. The overflow causes the calculated offset to wrap, resulting in a buffer underwrite that can corrupt memory and potentially allow an attacker to execute arbitrary code or crash the application. The flaw is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 4.8 (MEDIUM) - Published: 2025-05-06T15:16:05.320 - Last Modified: 2026-09-07T21:17:27.187
Original Description: A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite.
"If you have knowledge, let others light their candles in it."
— Margaret Fuller