Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-71120.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-71120
Upstream
Published
2025-11-26T15:15:51Z
Modified
2026-04-01T05:22:30.783484Z
Summary
CVE-2025-13601 affecting package glib for versions less than 2.78.6-5
Details

A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the gescapeuri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow, leading to a potential write off the end of the newly allocated string.

References

Affected packages

Azure Linux:3 / glib

Package

Name
glib
Purl
pkg:rpm/azure-linux/glib

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.78.6-5

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-71120.json"