Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-1489

Опубликовано: 27 янв. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.

Отчет

This vulnerability is rated Moderate for Red Hat products. A flaw in GLib's Unicode case conversion implementation can lead to memory corruption due to an integer overflow when processing specially crafted and extremely large Unicode strings. Applications that handle untrusted, large Unicode input and utilize GLib for string conversion may be susceptible, potentially resulting in crashes or instability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bootcFix deferred
Red Hat Enterprise Linux 10glib2Fix deferred
Red Hat Enterprise Linux 10glycin-loadersFix deferred
Red Hat Enterprise Linux 10loupeFix deferred
Red Hat Enterprise Linux 10mingw-glib2Fix deferred
Red Hat Enterprise Linux 10papersFix deferred
Red Hat Enterprise Linux 10rpm-ostreeFix deferred
Red Hat Enterprise Linux 6glib2Fix deferred
Red Hat Enterprise Linux 7glib2Fix deferred
Red Hat Enterprise Linux 8glib2Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2433348Glib: GLib: Memory corruption via integer overflow in Unicode case conversion

EPSS

Процентиль: 18%
0.00057
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
2 месяца назад

A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.

CVSS3: 5.4
nvd
2 месяца назад

A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.

CVSS3: 5.4
debian
2 месяца назад

A flaw was found in GLib. An integer overflow vulnerability in its Uni ...

CVSS3: 5.4
github
2 месяца назад

A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.

suse-cvrf
около 2 месяцев назад

Security update for glib2

EPSS

Процентиль: 18%
0.00057
Низкий

5.4 Medium

CVSS3