Logo
vulnerabilityCVE-2025-7039
Name
CVE-2025-7039
Source
NVD ( link)Debian ( link)
Description
A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
glib-2.0
Patched

Vulnerability Ratings#


3.7
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
2.72.3
Patched
yocto
master
2.88.1
Not Affected

Resolved with patches#


glib-2.0 (yocto:kirkstone)

#
Title
Author
Resolve
1
glib/gfileutils.c: use 64 bits for value in get_tmp_file()
Alexander Kanavin <alex@linutronix.de>
CVE-2025-7039
2
gfileutils: fix computation of temporary file name
Michael Catanzaro <mcatanzaro@redhat.com>
CVE-2025-7039

glib-2.0 (yocto:scarthgap)

#
Title
Author
Resolve
1
gfileutils: fix computation of temporary file name
Michael Catanzaro <mcatanzaro@redhat.com>
CVE-2025-7039