Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58013

Опубликовано: 03 апр. 2026
Источник: redhat
CVSS3: 6.5

Описание

A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.

Отчет

Any applications calling g_io_channel_set_line_term() with a multi-byte line terminator (length greater than one) and subsequently calling g_io_channel_read_line_backend() are vulnerable to this issue. This flaw can cause a buffer over-read of 8 bytes, leading to an information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary. Due to these reasons, this vulnerability has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this vulnerability, restrict any custom line terminator string passed to g_io_channel_set_line_term() to a maximum length of one byte before calling g_io_channel_read_line_backend(). Using the default line terminators will completely neutralize this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10glib2Affected
Red Hat Enterprise Linux 10mingw-glib2Affected
Red Hat Enterprise Linux 6glib2Affected
Red Hat Enterprise Linux 7glib2Affected
Red Hat Enterprise Linux 8glib2Affected
Red Hat Enterprise Linux 8mingw-glib2Affected
Red Hat Enterprise Linux 9glib2Affected
Red Hat Enterprise Linux 9mingw-glib2Affected
Red Hat Hardened Imagesglib2Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-126
https://bugzilla.redhat.com/show_bug.cgi?id=2492248glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.

CVSS3: 6.5
nvd
около 1 месяца назад

A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.

CVSS3: 6.5
msrc
23 дня назад

Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"

CVSS3: 6.5
debian
около 1 месяца назад

A flaw was found in GLib. A buffer over-read can occur in g_io_channel ...

CVSS3: 6.5
github
около 1 месяца назад

A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.

6.5 Medium

CVSS3