Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58013

Опубликовано: 03 апр. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.

Отчет

Any applications calling g_io_channel_set_line_term() with a multi-byte line terminator (length greater than one) and subsequently calling g_io_channel_read_line_backend() are vulnerable to this issue. This flaw can cause a buffer over-read of 8 bytes, leading to an information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary. Due to these reasons, this vulnerability has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this vulnerability, restrict any custom line terminator string passed to g_io_channel_set_line_term() to a maximum length of one byte before calling g_io_channel_read_line_backend(). Using the default line terminators will completely neutralize this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10mingw-glib2Affected
Red Hat Enterprise Linux 6glib2Will not fix
Red Hat Enterprise Linux 9mingw-glib2Affected
Red Hat Hardened Imagesglib2Not affected
Red Hat Enterprise Linux 10glib2FixedRHSA-2026:5701519.08.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportglib2FixedRHSA-2026:6576709.09.2026
Red Hat Enterprise Linux 7 Extended Lifecycle Supportglib2FixedRHSA-2026:6577309.09.2026
Red Hat Enterprise Linux 8mingw-glib2FixedRHSA-2026:4951203.08.2026
Red Hat Enterprise Linux 8glib2FixedRHSA-2026:6176631.08.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportglib2FixedRHSA-2026:6576209.09.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-126
https://bugzilla.redhat.com/show_bug.cgi?id=2492248glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"

EPSS

Процентиль: 41%
0.00501
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.

CVSS3: 6.5
nvd
3 месяца назад

A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.

CVSS3: 6.5
msrc
2 месяца назад

Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"

CVSS3: 6.5
debian
3 месяца назад

A flaw was found in GLib. A buffer over-read can occur in g_io_channel ...

CVSS3: 6.5
github
3 месяца назад

A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.

EPSS

Процентиль: 41%
0.00501
Низкий

6.5 Medium

CVSS3