CVE-2025-60019: NULL Pointer Dereference
glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location.
AI Analysis
Technical Summary
The vulnerability in glib-networking's OpenSSL backend arises from improper handling of memory allocation return values. Specifically, when an out of memory condition occurs, the failure to check the return value can cause the program to dereference a NULL pointer, potentially leading to a write to an invalid memory location. This can cause a denial of service or application crash but does not impact confidentiality or integrity. The vulnerability is assigned CVE-2025-60019 with a CVSS 3.1 base score of 3.7 (low severity). It affects version 2.60 of glib-networking. The Red Hat advisory linked does not explicitly state patch availability or remediation status.
Potential Impact
The impact is limited to availability, potentially causing application crashes or denial of service due to NULL pointer dereference when memory allocation fails. There is no impact on confidentiality or integrity. No known exploits have been reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory at https://access.redhat.com/security/cve/CVE-2025-60019 for current remediation guidance. Until a patch is available, users should monitor vendor communications for updates. No specific workaround or mitigation is provided in the advisory.
CVE-2025-60019: NULL Pointer Dereference
Description
glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location.
CVSS v3.1
Score 3.7low
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in glib-networking's OpenSSL backend arises from improper handling of memory allocation return values. Specifically, when an out of memory condition occurs, the failure to check the return value can cause the program to dereference a NULL pointer, potentially leading to a write to an invalid memory location. This can cause a denial of service or application crash but does not impact confidentiality or integrity. The vulnerability is assigned CVE-2025-60019 with a CVSS 3.1 base score of 3.7 (low severity). It affects version 2.60 of glib-networking. The Red Hat advisory linked does not explicitly state patch availability or remediation status.
Potential Impact
The impact is limited to availability, potentially causing application crashes or denial of service due to NULL pointer dereference when memory allocation fails. There is no impact on confidentiality or integrity. No known exploits have been reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory at https://access.redhat.com/security/cve/CVE-2025-60019 for current remediation guidance. Until a patch is available, users should monitor vendor communications for updates. No specific workaround or mitigation is provided in the advisory.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- redhat
- Date Reserved
- 2025-09-24T12:21:36.721Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2025-60019","vendor":"Red Hat"}]
Threat ID: 68d56693c17b2efb31c3d01b
Added to database: 09/25/2025, 15:58:11 UTC
Last enriched: 07/02/2026, 21:59:42 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 191
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.