Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-0988

Опубликовано: 21 янв. 2026
Источник: debian

Описание

A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glib2.0fixed2.87.1-1experimentalpackage
glib2.0fixed2.86.3-5package
glib2.0fixed2.84.4-3~deb13u3trixiepackage
glib2.0fixed2.74.6-2+deb12u9bookwormpackage

Примечания

  • https://gitlab.gnome.org/GNOME/glib/-/issues/3851

  • Fixed by: https://gitlab.gnome.org/GNOME/glib/-/commit/c5766cff61ffce0b8e787eae09908ac348338e5f (2.87.1)

Связанные уязвимости

CVSS3: 3.7
ubuntu
7 месяцев назад

A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).

CVSS3: 3.7
redhat
7 месяцев назад

A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).

CVSS3: 3.7
nvd
7 месяцев назад

A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).

suse-cvrf
6 месяцев назад

Security update for glib2

suse-cvrf
7 месяцев назад

Security update for glib2