CVE-2025-60018 MEDIUM

CVE-2025-60018: Glib-networking: out of bound reads on glib-networking through tls/openssl/gtlscertificate-openssl.c via "g_tls_certificate_openssl_get_property()"

Vendor Red Hat
Product Red Hat Enterprise Linux 10
Weakness CWE-125
Published September 25, 2025
Last update November 21, 2025

CVSS base score

4.8/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L

What the vulnerability does

01Description

glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out of bounds read.

Key dates

02Disclosure timeline

September 25, 2025 CVE published
November 21, 2025 Record updated