[CLSA-2026:1771857684] Fix CVE(s): CVE-2025-14087, CVE-2025-14512
Type:
security
Severity:
Critical
Release date:
2026-02-23 14:41:28 UTC
Description:
* SECURITY UPDATE: Buffer underflow in GVariant parser leads to heap corruption - debian/patches/CVE-2025-14087_14512.patch: Fix integer overflows in GVariant text format parser when processing input longer than INT_MAX - CVE-2025-14087 * SECURITY UPDATE: Integer overflow in escape_byte_string() leads to heap buffer overflow - debian/patches/CVE-2025-14087_14512.patch: Fix integer overflow in escape_byte_string() for byte strings with many invalid characters - CVE-2025-14512
Updated packages:
  • libglib2.0-0_2.48.2-0ubuntu4.8+tuxcare.els5_amd64.deb
    sha:12dfa91a47a72fc9cac568cc2e247c38a8debbf7
  • libglib2.0-0-refdbg_2.48.2-0ubuntu4.8+tuxcare.els5_amd64.deb
    sha:71b2cddca05f9a21b5d7c5d03b50769ae1cad602
  • libglib2.0-bin_2.48.2-0ubuntu4.8+tuxcare.els5_amd64.deb
    sha:04ca7a135524851fb9be32838b871a3d7f9553b0
  • libglib2.0-data_2.48.2-0ubuntu4.8+tuxcare.els5_all.deb
    sha:9bc7dfc302f6f1e01c398deff04c2f6aa42cfd15
  • libglib2.0-dev_2.48.2-0ubuntu4.8+tuxcare.els5_amd64.deb
    sha:757bbc95133c2bb603ef852e4f3bce0274e010df
  • libglib2.0-doc_2.48.2-0ubuntu4.8+tuxcare.els5_all.deb
    sha:0039caa4d5bbc26b9d3e1c3413ad60289327c77f
  • libglib2.0-tests_2.48.2-0ubuntu4.8+tuxcare.els5_amd64.deb
    sha:cb2877adbf9e037cd05f0bc246b919859250a8f6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.