CVE-2025-7039
Publication date 3 September 2025
Last updated 10 February 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.
Read the notes from the security team
Why is this CVE low priority?
Security impact is quite limited
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| glib2.0 | 25.10 questing |
Not affected
|
| 24.04 LTS noble |
Fixed 2.80.0-6ubuntu3.6
|
|
| 22.04 LTS jammy |
Fixed 2.72.4-0ubuntu2.7
|
|
| 20.04 LTS focal |
Fixed 2.64.6-1~ubuntu20.04.9+esm1
|
|
| 18.04 LTS bionic |
Fixed 2.56.4-0ubuntu0.18.04.9+esm5
|
|
| 16.04 LTS xenial |
Fixed 2.48.2-0ubuntu4.8+esm5
|
|
| 14.04 LTS trusty |
Fixed 2.40.2-0ubuntu1.1+esm7
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialNotes
mdeslaur
Per upstream bug, the security impact of this issue is quite limited, setting priority to low
Patch details
| Package | Patch details |
|---|---|
| glib2.0 |
|
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Network |
| Attack complexity | High |
| Privileges required | None |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | None |
| Integrity impact | Low |
| Availability impact | None |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
References
Related Ubuntu Security Notices (USN)
- USN-7942-1
- GLib vulnerabilities
- 6 January 2026
- USN-7942-2
- GLib vulnerabilities
- 10 February 2026