CVE-2025-60019
3.7
LOW
CVSS 3.1
EPSS 0.04%
Description
glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location.
How to fix CVE-2025-60019
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/glib-networking—no fix listed
Is CVE-2025-60019 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.7 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |