Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-66780.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-66780
Upstream
Published
2025-09-03T02:15:38Z
Modified
2026-04-01T05:21:47.051296Z
Summary
CVE-2025-7039 affecting package glib for versions less than 2.71.0-6
Details

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.

References

Affected packages

Azure Linux:2 / glib

Package

Name
glib
Purl
pkg:rpm/azure-linux/glib

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.71.0-6

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-66780.json"