Description
An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption.
References (7)
Scores
CVSS v3
7.5
EPSS
0.0137
EPSS Percentile
80.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-681
Status
published
Products (8)
broadcom/brocade_fabric_operating_system_firmware
debian/debian_linux
9.0
fedoraproject/fedora
33
fedoraproject/fedora
34
gnome/glib
< 2.66.6
netapp/active_iq_unified_manager
netapp/cloud_backup
netapp/e-series_performance_analyzer
Published
Feb 15, 2021
Tracked Since
Feb 18, 2026