Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21410-1

Опубликовано: 22 июл. 2026
Источник: suse-cvrf

Описание

Security update for glib2

This update for glib2 fixes the following issues:

  • CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009).
  • CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010).
  • CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016).
  • CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018).
  • CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021).
  • CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008).

Список пакетов

openSUSE Leap 16.0
gio-branding-upstream-2.84.4-160000.4.1
glib2-devel-2.84.4-160000.4.1
glib2-devel-static-2.84.4-160000.4.1
glib2-doc-2.84.4-160000.4.1
glib2-lang-2.84.4-160000.4.1
glib2-tests-devel-2.84.4-160000.4.1
glib2-tools-2.84.4-160000.4.1
libgio-2_0-0-2.84.4-160000.4.1
libgirepository-2_0-0-2.84.4-160000.4.1
libglib-2_0-0-2.84.4-160000.4.1
libgmodule-2_0-0-2.84.4-160000.4.1
libgobject-2_0-0-2.84.4-160000.4.1
libgthread-2_0-0-2.84.4-160000.4.1
typelib-1_0-GIRepository-3_0-2.84.4-160000.4.1
typelib-1_0-GLib-2_0-2.84.4-160000.4.1
typelib-1_0-GLibUnix-2_0-2.84.4-160000.4.1
typelib-1_0-GModule-2_0-2.84.4-160000.4.1
typelib-1_0-GObject-2_0-2.84.4-160000.4.1
typelib-1_0-Gio-2_0-2.84.4-160000.4.1

Описание

A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.


Затронутые продукты
openSUSE Leap 16.0:gio-branding-upstream-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-devel-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-devel-static-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-doc-2.84.4-160000.4.1

Ссылки

Описание

A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.


Затронутые продукты
openSUSE Leap 16.0:gio-branding-upstream-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-devel-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-devel-static-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-doc-2.84.4-160000.4.1

Ссылки

Описание

A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.


Затронутые продукты
openSUSE Leap 16.0:gio-branding-upstream-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-devel-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-devel-static-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-doc-2.84.4-160000.4.1

Ссылки

Описание

A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.


Затронутые продукты
openSUSE Leap 16.0:gio-branding-upstream-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-devel-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-devel-static-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-doc-2.84.4-160000.4.1

Ссылки

Описание

A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.


Затронутые продукты
openSUSE Leap 16.0:gio-branding-upstream-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-devel-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-devel-static-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-doc-2.84.4-160000.4.1

Ссылки

Описание

A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> or <arg>. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.


Затронутые продукты
openSUSE Leap 16.0:gio-branding-upstream-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-devel-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-devel-static-2.84.4-160000.4.1
openSUSE Leap 16.0:glib2-doc-2.84.4-160000.4.1

Ссылки