Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-0988

Опубликовано: 15 янв. 2026
Источник: redhat
CVSS3: 3.7

Описание

A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).

Отчет

This vulnerability is rated Moderate for Red Hat. An integer overflow in the g_buffered_input_stream_peek() function of the GLib library can lead to a Denial of Service. Exploitation requires specially crafted input and is subject to strict preconditions, primarily causing application crashes.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bootcFix deferred
Red Hat Enterprise Linux 10glib2Fix deferred
Red Hat Enterprise Linux 10glycin-loadersFix deferred
Red Hat Enterprise Linux 10loupeFix deferred
Red Hat Enterprise Linux 10mingw-glib2Fix deferred
Red Hat Enterprise Linux 10papersFix deferred
Red Hat Enterprise Linux 10rpm-ostreeFix deferred
Red Hat Enterprise Linux 6glib2Fix deferred
Red Hat Enterprise Linux 7glib2Fix deferred
Red Hat Enterprise Linux 8glib2Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2429886glib: GLib: Denial of Service via Integer Overflow in g_buffered_input_stream_peek()

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
2 месяца назад

A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).

CVSS3: 3.7
nvd
2 месяца назад

A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).

CVSS3: 3.7
debian
2 месяца назад

A flaw was found in glib. Missing validation of offset and count param ...

suse-cvrf
около 2 месяцев назад

Security update for glib2

suse-cvrf
2 месяца назад

Security update for glib2

3.7 Low

CVSS3