7.7highHigh

CVE-2025-13601

Redhat Codeready Linux Builder

A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.

Exploitation status

  • Published references include exploit or proof-of-concept material. There is no confirmation it is being used in real attacks.
  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is requires local access to the machine.
  • For an attacker who can reach it, no special conditions are needed to exploit it.
  • To exploit it, no account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
7.7 (v3.1)
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Weakness
CWE-190
Assigned by
secalert@redhat.com

Dates

Published
2025-11-26
Last modified
2026-08-31
Sources
NVD

Affected products

  • Redhat Codeready Linux Builder9.0
  • Redhat Codeready Linux Builder For Ibm Z Systems9.0 s390x, 10.0 s390x, 8.0 s390x, 9.4 s390x, 9.6 s390x
  • Redhat Codeready Linux Builder For Power Little Endian9.0 ppc64le, 10.0 ppc64le, 8.0 ppc64le, 9.4 ppc64le, 9.6 ppc64le
  • Redhat Codeready Linux Builder For X86 649.0, 10.0, 8.0, 9.4, 9.6
  • Redhat Enterprise Linux For Arm 649.0, 10.0, 8.0, 9.2, 9.4, 9.6
  • Redhat Enterprise Linux For Ibm Z Systems9.0 s390x, 10.0 s390x, 8.0 s390x, 9.2 s390x, 9.4 s390x, 9.6 s390x
  • Redhat Enterprise Linux For Power Little Endian9.0 ppc64le, 10.0 ppc64le, 8.0 ppc64le, 9.2 ppc64le, 9.4 ppc64le, 9.6 ppc64le
  • Redhat Enterprise Linux For X86 649.0, 10.0, 8.0, 9.2, 9.4, 9.6, 8.6, 8.8
  • Redhat Codeready Linux Builder For Arm6410.0, 8.0, 9.6
  • Redhat Enterprise Linux Server Aus9.2, 9.4, 9.6, 8.6, 8.4, 8.2
  • Redhat Codeready Linux Builder For Arm64 Eus9.4, 10.0
  • Redhat Enterprise Linux For X86 64 Eus9.4, 10.0, 9.6, 8.6, 8.8, 8.4

As listed in the NVD configuration data. Not a statement about your estate.

References