CVE-2025-2722
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 1333
Summary
CVE-2025-2722 is a newly disclosed critical vulnerability affecting GNOME libgsf up to version 1.14.53. This issue lies in the function gsf_prop_settings_collect_va, where the manipulation of the argument 'n_alloced_params' leads to a heap-based buffer overflow. A local attacker can exploit this vulnerability by providing specially crafted input. Despite early disclosure to the vendor, they have not responded to the issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.