glib2-2.56.4-177.el8_10
エラータID: AXSA:2026-1730:14
GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.
Security Fix(es):
* glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() (CVE-2026-58010)
* glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime (CVE-2026-58011)
* glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() (CVE-2026-58012)
* glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" (CVE-2026-58013)
* glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" (CVE-2026-58014)
* glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive (CVE-2026-58015)
* GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering (CVE-2026-15588)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-15588
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.
CVE-2026-58010
A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.
CVE-2026-58011
A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.
CVE-2026-58012
A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.
CVE-2026-58013
A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.
CVE-2026-58014
A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.
CVE-2026-58015
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
Update packages.
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.
A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.
A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.
A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.
A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.
A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
N/A
SRPMS
- glib2-2.56.4-177.el8_10.src.rpm
MD5: d4ad19e84780bfeeb3660f9457cfef7b
SHA-256: a37a574f4435dbfdd329ac2bd1e251512d13b0eba06d9b56b2706d802540f015
Size: 6.86 MB
Asianux Server 8 for x86_64
- glib2-2.56.4-177.el8_10.i686.rpm
MD5: e055c1d0a5b1d88ce026ccafd1b89e0a
SHA-256: cb659ed38868c1bb7513fea364a6ab68f6a16ce1196fb22276207f57301f5643
Size: 2.59 MB - glib2-2.56.4-177.el8_10.x86_64.rpm
MD5: b523b6c50ae67def5db9fc4bdd134697
SHA-256: 4109522e22bb930461b89810d1cf494fb44d0dae56348e40d0ebd852f9e01c53
Size: 2.50 MB - glib2-devel-2.56.4-177.el8_10.i686.rpm
MD5: 1fcd054411767320d3492a034e0c7261
SHA-256: 32b60bf841d370e2bfab06838bd44dca6f517fa23da546c7668bd1b19520133d
Size: 427.39 kB - glib2-devel-2.56.4-177.el8_10.x86_64.rpm
MD5: 90a41ce7d18efec2bc03e8c65e1c1163
SHA-256: fe54b72179eee2dec8637fc1246fe8167a4c9c7b51e817ddbb9dc69a7f98ee71
Size: 425.80 kB - glib2-doc-2.56.4-177.el8_10.noarch.rpm
MD5: 13faa1284e5f7f0666d1ca74e92f6fcb
SHA-256: 8761223fea430e8915b491cfc6de064b485feb17fb8a59ac8163dca3fe10456a
Size: 1.57 MB - glib2-fam-2.56.4-177.el8_10.x86_64.rpm
MD5: 1cfb761a3d7b5913d319d2525b2850be
SHA-256: e78e279a385d5715af9290877c8e5ea5038dae03653917a063180c67217070a5
Size: 13.82 kB - glib2-static-2.56.4-177.el8_10.i686.rpm
MD5: f6d1229dc77d44ab5f00e77dfba11c19
SHA-256: bb642583c4ed5609050644742f1d0f52e7b3216bf194ec665bf381c84c1a7639
Size: 1.68 MB - glib2-static-2.56.4-177.el8_10.x86_64.rpm
MD5: 5a302e30e6f7a07f065a36424baf5903
SHA-256: a519ec07390ff84f4bb0711728dcf5db096e4d613b1942901295e53c6f801212
Size: 1.53 MB - glib2-tests-2.56.4-177.el8_10.x86_64.rpm
MD5: 604f3b3192a7069d4de5d1de4466070d
SHA-256: fcb8cd51c63f7183d5c1389fc447905ebcd5925106d4581651b0ce34d47926b8
Size: 1.77 MB