VDB

ANCHORE-2025-6052

ANCHORE-2025-6052 PUBLISHED

A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the allocated memory, leading to crashes or memory corruption.

Affected Products

VendorProductVersions
GNOMEGLib2.75.3
Oracle CorporationOpenJDK1.9, 0, 1.9
Oracle CorporationOracle Java SE0, 1.9, 1.9
Oracle CorporationOpenJFX12, 18, 22

Timeline

  • Jun 13, 2025 CVE Published
  • Nov 7, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›