Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58016

Опубликовано: 08 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a element nested within other elements like , , or . This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.

A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a node element nested within other elements like method, signal, property or arg. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.

Отчет

Any applications processing D-Bus introspection XML input from untrusted sources with g_dbus_node_info_new_for_xml() are vulnerable to this issue. In GLib itself, the gdbus command line tool is the primary vector for local exploitation. However, other applications using the vulnerable function may process untrusted input in a way that allows a remote attacker to trigger this flaw. This vulnerability can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service. As this vulnerability allows a remote attacker to cause a denial of service, it has been rated with an important severity.

Меры по смягчению последствий

To mitigate this vulnerability, implement input validation to sanitize untrusted D-Bus introspection XML, specifically rejecting malformed structures such as elements improperly nested within , , or elements before calling g_dbus_node_info_new_for_xml(). Alternatively, restricting the application to only process XML input from trusted, authenticated sources will completely neutralize this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10mingw-glib2Affected
Red Hat Enterprise Linux 6glib2Affected
Red Hat Enterprise Linux 7glib2Affected
Red Hat Enterprise Linux 8mingw-glib2Affected
Red Hat Enterprise Linux 9mingw-glib2Affected
Red Hat Hardened Imagesglib2Not affected
Red Hat Enterprise Linux 10glib2FixedRHSA-2026:4206320.07.2026
Red Hat Enterprise Linux 8glib2FixedRHSA-2026:4209020.07.2026
Red Hat Enterprise Linux 9glib2FixedRHSA-2026:4208920.07.2026
Red Hat Enterprise Linux 9glib2FixedRHSA-2026:4208920.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-191
https://bugzilla.redhat.com/show_bug.cgi?id=2492257glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"

EPSS

Процентиль: 29%
0.00373
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> or <arg>. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.

CVSS3: 7.5
nvd
около 1 месяца назад

A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.

CVSS3: 7.5
msrc
около 1 месяца назад

Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"

CVSS3: 7.5
debian
около 1 месяца назад

A flaw was found in GLib. A state confusion issue exists in g_dbus_nod ...

rocky
10 дней назад

Important: glib2 security update

EPSS

Процентиль: 29%
0.00373
Низкий

7.5 High

CVSS3