7.7High

Redhat Codeready Linux Builder

CVE-2025-13601

A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.

What this means for your business

  • It affects Redhat Codeready Linux Builder. It matters if your company, or a supplier that handles your data, runs it.
  • Code showing how to exploit it has been published, but real attacks have not been confirmed.
  • An attacker can use it only with access to the machine itself, without a login, and without anyone at your company clicking anything.
  • FIRST's prediction model gives it a 0.3% chance of attack attempts being seen in the next 30 days, ranking above 25% of all known flaws.

What to do

  1. 1Check whether your company or your suppliers run Redhat Codeready Linux Builder, and which version. The affected versions are listed further down this page.
  2. 2If you do, apply the vendor's fix. A patch or vendor advisory has been published.

Not sure if your company is exposed?

Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.

Scoring

CVSS
7.7 (v3.1)
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Weakness
CWE-190
Assigned by
secalert@redhat.com

Dates

Published
2025-11-26
Last modified
2026-08-31
Sources
NVD

Affected products

  • Redhat Codeready Linux Builder9.0
  • Redhat Codeready Linux Builder For Ibm Z Systems9.0 s390x, 10.0 s390x, 8.0 s390x, 9.4 s390x, 9.6 s390x
  • Redhat Codeready Linux Builder For Power Little Endian9.0 ppc64le, 10.0 ppc64le, 8.0 ppc64le, 9.4 ppc64le, 9.6 ppc64le
  • Redhat Codeready Linux Builder For X86 649.0, 10.0, 8.0, 9.4, 9.6
  • Redhat Enterprise Linux For Arm 649.0, 10.0, 8.0, 9.2, 9.4, 9.6
  • Redhat Enterprise Linux For Ibm Z Systems9.0 s390x, 10.0 s390x, 8.0 s390x, 9.2 s390x, 9.4 s390x, 9.6 s390x
  • Redhat Enterprise Linux For Power Little Endian9.0 ppc64le, 10.0 ppc64le, 8.0 ppc64le, 9.2 ppc64le, 9.4 ppc64le, 9.6 ppc64le
  • Redhat Enterprise Linux For X86 649.0, 10.0, 8.0, 9.2, 9.4, 9.6, 8.6, 8.8
  • Redhat Codeready Linux Builder For Arm6410.0, 8.0, 9.6
  • Redhat Enterprise Linux Server Aus9.2, 9.4, 9.6, 8.6, 8.4, 8.2
  • Redhat Codeready Linux Builder For Arm64 Eus9.4, 10.0
  • Redhat Enterprise Linux For X86 64 Eus9.4, 10.0, 9.6, 8.6, 8.8, 8.4

As listed in the NVD configuration data. Not a statement about your estate.

References