Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-1485

Опубликовано: 27 янв. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 2.8

Описание

A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.

РелизСтатусПримечание
devel

released

2.87.2-2
esm-infra-legacy/trusty

needed

esm-infra-legacy/xenial

needed

esm-infra/bionic

needed

esm-infra/focal

needed

esm-infra/xenial

ignored

end of ESM support, was needed
jammy

released

2.72.4-0ubuntu2.9
noble

released

2.80.0-6ubuntu3.8
questing

released

2.86.0-2ubuntu0.3
resolute

released

2.87.2-2

Показывать по

EPSS

Процентиль: 4%
0.00139
Низкий

2.8 Low

CVSS3

Связанные уязвимости

CVSS3: 2.8
redhat
7 месяцев назад

A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.

CVSS3: 2.8
nvd
7 месяцев назад

A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.

CVSS3: 2.8
debian
7 месяцев назад

A flaw was found in Glib's content type parsing logic. This buffer und ...

CVSS3: 2.8
github
7 месяцев назад

A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.

CVSS3: 2.8
fstec
8 месяцев назад

Уязвимость функции parse_header() набора библиотек GLib, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 4%
0.00139
Низкий

2.8 Low

CVSS3