Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-1485

Опубликовано: 27 янв. 2026
Источник: redhat
CVSS3: 2.8
EPSS Низкий

Описание

A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.

Отчет

This vulnerability is rated Low for Red Hat. Exploitation requires a local user to install or process a specially crafted treemagic file, which limits the practical impact to local denial of service or application instability. Red Hat products are affected where GLib is used to process untrusted treemagic files.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bootcFix deferred
Red Hat Enterprise Linux 10glib2Fix deferred
Red Hat Enterprise Linux 10glycin-loadersFix deferred
Red Hat Enterprise Linux 10loupeFix deferred
Red Hat Enterprise Linux 10mingw-glib2Fix deferred
Red Hat Enterprise Linux 10papersFix deferred
Red Hat Enterprise Linux 10rpm-ostreeFix deferred
Red Hat Enterprise Linux 6glib2Fix deferred
Red Hat Enterprise Linux 7glib2Fix deferred
Red Hat Enterprise Linux 8glib2Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-124
https://bugzilla.redhat.com/show_bug.cgi?id=2433325Glib: Glib: Local denial of service via buffer underflow in content type parsing

EPSS

Процентиль: 0%
0.00005
Низкий

2.8 Low

CVSS3

Связанные уязвимости

CVSS3: 2.8
ubuntu
2 месяца назад

A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.

CVSS3: 2.8
nvd
2 месяца назад

A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.

CVSS3: 2.8
debian
2 месяца назад

A flaw was found in Glib's content type parsing logic. This buffer und ...

CVSS3: 2.8
github
2 месяца назад

A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.

suse-cvrf
около 2 месяцев назад

Security update for glib2

EPSS

Процентиль: 0%
0.00005
Низкий

2.8 Low

CVSS3