ALSA-2025:11140

Source
https://errata.almalinux.org/9/ALSA-2025-11140.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2025:11140.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2025:11140
Related
Published
2025-07-15T00:00:00Z
Modified
2025-07-16T12:44:37Z
Summary
Moderate: glib2 security update
Details

GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.

Security Fix(es):

  • glib: buffer overflow in setconnectmsg() (CVE-2024-52533)
  • glib: Buffer Underflow on GLib through glib/gstring.c via function gstringinsert_unichar (CVE-2025-4373)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:9 / glib2

Package

Name
glib2
Purl
pkg:rpm/almalinux/glib2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.68.4-16.el9_6.2

AlmaLinux:9 / glib2-devel

Package

Name
glib2-devel
Purl
pkg:rpm/almalinux/glib2-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.68.4-16.el9_6.2

AlmaLinux:9 / glib2-doc

Package

Name
glib2-doc
Purl
pkg:rpm/almalinux/glib2-doc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.68.4-16.el9_6.2

AlmaLinux:9 / glib2-static

Package

Name
glib2-static
Purl
pkg:rpm/almalinux/glib2-static

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.68.4-16.el9_6.2

AlmaLinux:9 / glib2-tests

Package

Name
glib2-tests
Purl
pkg:rpm/almalinux/glib2-tests

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.68.4-16.el9_6.2