Logo
vulnerabilityCVE-2025-60019
Name
CVE-2025-60019
Source
NVD ( link)Debian ( link)
Description
glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
glib-networking
Patched

Vulnerability Ratings#


3.7
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.76.0
Not Affected
buildroot
master
2.76.0
Not Affected
openwrt
master
2.80.1-r1
Not Affected
openwrt
openwrt-25.12
2.80.1-r1
Not Affected
yocto
master
2.80.1
Patched
yocto
scarthgap
2.78.1
Patched

Resolved with patches#


glib-networking (yocto:kirkstone)

#
Title
Author
Resolve
1
openssl: check return values of BIO_new()
Michael Catanzaro <mcatanzaro@redhat.com>
CVE-2025-60019

glib-networking (yocto:master)

#
Title
Author
Resolve
1
openssl: check return values of BIO_new()
Michael Catanzaro <mcatanzaro@redhat.com>
CVE-2025-60019
2
openssl: check return value of g_tls_bio_alloc()
Michael Catanzaro <mcatanzaro@redhat.com>
CVE-2025-60019

glib-networking (yocto:scarthgap)

#
Title
Author
Resolve
1
openssl: check return values of BIO_new()
Michael Catanzaro <mcatanzaro@redhat.com>
CVE-2025-60019