Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-3360

17
FAUCET Score

CVE-2025-3360 describes an integer overflow and buffer under-read vulnerability within GLib's g_date_time_new_from_iso8601() function, triggered by parsing malformed ISO 8601 timestamps. This flaw has a low severity CVSS score of 3.7, indicating a network attack vector with high attack complexity and a potential impact of only low availability. There is no evidence of active exploitation, no public exploit code available, and minimal community discussion or media coverage, with a single mention related to Siemens SINEC OS.

Impacted Technologies

VendorProductVersion(s)CPE
Red HatRed Hat Enterprise Linux 10
All Versions ImpactedCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 6
Range not provided by sourceCNA affecteddefault unknown
Red HatRed Hat Enterprise Linux 7
Range not provided by sourceCNA affecteddefault unknown
Red HatRed Hat Enterprise Linux 8
All Versions ImpactedCNA affecteddefault affected
Red HatRed Hat Enterprise Linux 9
All Versions ImpactedCNA affecteddefault affected

CVSS Data

CVSS version used by this source: 3.1

3.7LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.2
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.45%
Probability of exploitation in next 30 days
EPSS Percentile
36.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0045 is in the 23rd percentile among its peer group of 1,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (18)

microsoftpatch availablevia msrc
Product: 19553-16823Fixed in: 2.71.0-5
microsoftpatch availablevia msrc
Product: 19898-17086Fixed in: 2.71.0-5
microsoftpatch availablevia msrc
Product: 19598-17084Fixed in: 2.78.6-2
microsoftpatch availablevia msrc
Product: cm2 glib 2.71.0-5 on CBL Mariner 2.0Fixed in: 2.71.0-5
microsoftpatch availablevia msrc
Product: cbl2 glib 2.71.0-5 on CBL Mariner 2.0Fixed in: 2.71.0-5
microsoftpatch availablevia msrc
Product: azl3 glib 2.78.6-2 on Azure Linux 3.0Fixed in: 2.78.6-2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: librsvg2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: mingw-glib2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: bootc
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: bootc
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: librsvg2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: mingw-glib2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: glib2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: glib2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: glycin-loaders
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: loupe
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: mingw-glib2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: glib2

Vendor Advisories (2)

microsoft2025-Apr/CVE-2025-3360Low

Glibc: glib prior to 2.82.5 is vulnerable to integer overflow and buffer under-read when parsing a very long invalid iso 8601 timestamp with g_date_time_new_from_iso8601().

Apr 8, 2025
redhatCVE-2025-3360Low

glibc: GLib prior to 2.82.5 is vulnerable to integer overflow and buffer under-read when parsing a very long invalid ISO 8601 timestamp with g_date_time_new_from_iso8601().

Apr 7, 2025

References

gitlab.gnome.org / GNOME/glib/-/work_items/3647
lists.debian.org / debian-lts-announce/2025/04/msg00024.html
access.redhat.com / security/cve/CVE-2025-3360
bugzilla.redhat.com / show_bug.cgi
gitlab.gnome.org / GNOME/glib/-/issues/3647