glib2-2.68.4-19.el9_8.9
エラータID: AXSA:2026-1638:13
GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.
Security Fix(es):
* glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() (CVE-2026-58010)
* glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime (CVE-2026-58011)
* glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() (CVE-2026-58012)
* glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" (CVE-2026-58013)
* glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" (CVE-2026-58014)
* glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive (CVE-2026-58015)
* GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering (CVE-2026-15588)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-15588
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.
CVE-2026-58010
A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.
CVE-2026-58011
A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.
CVE-2026-58012
A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.
CVE-2026-58013
A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.
CVE-2026-58014
A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.
CVE-2026-58015
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
Update packages.
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.
A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.
A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.
A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.
A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.
A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
N/A
SRPMS
- glib2-2.68.4-19.el9_8.9.src.rpm
MD5: dc255d62d508a8d3fbceeee66ce5dabe
SHA-256: 3cea3c37b3e0cd0eb7d1cd0ef096750c0629eaee8c068e1a8ebfdf5f9e597e96
Size: 4.87 MB
Asianux Server 9 for x86_64
- glib2-2.68.4-19.el9_8.9.i686.rpm
MD5: 32d9c4f46d9dad241c43629377276105
SHA-256: 4311b789c5d65bf6ffcac806a195562304aaaeaa498e38d55cea8e751c3f63a6
Size: 2.72 MB - glib2-2.68.4-19.el9_8.9.x86_64.rpm
MD5: 3da3e81f9793f9c4debd3249b63cba42
SHA-256: 2c61cc4468966a24fd25dd0a4921cab449f23fafbb4a6574f5f2d231a0f0c745
Size: 2.64 MB - glib2-devel-2.68.4-19.el9_8.9.i686.rpm
MD5: e61ed70d314b15d5b99b16d3e940f330
SHA-256: af7135cab022adfc36da9de427361206ab2b536cab64959837182639635e23d7
Size: 548.78 kB - glib2-devel-2.68.4-19.el9_8.9.x86_64.rpm
MD5: 6c773ecb40070d49ef6910af54ac5bbb
SHA-256: 72ce6ff925e640ff488f6d78243f8599205b33f6ad06268c9d4c661806ca9690
Size: 547.37 kB - glib2-doc-2.68.4-19.el9_8.9.noarch.rpm
MD5: dfb2e077440a57305d1dcc10745bb0c4
SHA-256: a582b34c9c355c708a987b48b508b8d3e31c4e6108e9cc1e910734e5a4fa2f52
Size: 1.48 MB - glib2-static-2.68.4-19.el9_8.9.i686.rpm
MD5: d164719036faf8fd303562714942a265
SHA-256: f0aea2a37dea504f944e3fc963c3fc09aa5bbdeeadf7270709311d3acc050c63
Size: 1.51 MB - glib2-static-2.68.4-19.el9_8.9.x86_64.rpm
MD5: ce297c074ee698810162286407a269b5
SHA-256: a14da535d76ef3ffec4a25b01262e65d63b75939bc3acaa8db0a464269367f2f
Size: 1.39 MB - glib2-tests-2.68.4-19.el9_8.9.x86_64.rpm
MD5: 3cb71faee719cfc5ba9a9845d706f032
SHA-256: eb89461c515acbd4ffd810870cc3ddbe7e9e8c22252cdd143d689de4d6fd86f5
Size: 1.93 MB