[CLSA-2026:1771857969] Fix CVE(s): CVE-2025-14087, CVE-2025-14512
Type:
security
Severity:
Critical
Release date:
2026-02-23 14:46:14 UTC
Description:
* SECURITY UPDATE: Buffer underflow in GVariant parser leads to heap corruption - debian/patches/CVE-2025-14087_14512.patch: Fix integer overflows in GVariant text format parser when processing input longer than INT_MAX - CVE-2025-14087 * SECURITY UPDATE: Integer overflow in escape_byte_string() leads to heap buffer overflow - debian/patches/CVE-2025-14087_14512.patch: Fix integer overflow in escape_byte_string() for byte strings with many invalid characters - CVE-2025-14512
Updated packages:
  • libglib2.0-0_2.56.4-0ubuntu0.18.04.9+tuxcare.els4_amd64.deb
    sha:a99a3233bc0624e1476b8e56c709fa776db8a6cf
  • libglib2.0-bin_2.56.4-0ubuntu0.18.04.9+tuxcare.els4_amd64.deb
    sha:50b65753e933c18c80a3279096138fc166d0e1c5
  • libglib2.0-data_2.56.4-0ubuntu0.18.04.9+tuxcare.els4_all.deb
    sha:dc1f9a7944a47271d3e7c92a0df18f9f347bf18e
  • libglib2.0-dev_2.56.4-0ubuntu0.18.04.9+tuxcare.els4_amd64.deb
    sha:bd63f147c239f36a4446db4a42306e3604f88e16
  • libglib2.0-dev-bin_2.56.4-0ubuntu0.18.04.9+tuxcare.els4_amd64.deb
    sha:13d6c8afb7420d634a76bd2a67fe0245dbb37607
  • libglib2.0-doc_2.56.4-0ubuntu0.18.04.9+tuxcare.els4_all.deb
    sha:09127e3e86b2fc08be42f3a1cf3430a68dae905b
  • libglib2.0-tests_2.56.4-0ubuntu0.18.04.9+tuxcare.els4_amd64.deb
    sha:fc8660f2f804760304cb13daaf38cb5397f95780
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.