Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-1489

Опубликовано: 27 янв. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 5.4

Описание

A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.

РелизСтатусПримечание
devel

released

2.87.2-2
esm-infra-legacy/trusty

needed

esm-infra-legacy/xenial

needed

esm-infra/bionic

needed

esm-infra/focal

needed

esm-infra/xenial

ignored

end of ESM support, was needed
jammy

released

2.72.4-0ubuntu2.9
noble

released

2.80.0-6ubuntu3.8
questing

released

2.86.0-2ubuntu0.3
resolute

released

2.87.2-2

Показывать по

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
redhat
7 месяцев назад

A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.

CVSS3: 5.4
nvd
7 месяцев назад

A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.

CVSS3: 5.4
debian
7 месяцев назад

A flaw was found in GLib. An integer overflow vulnerability in its Uni ...

CVSS3: 5.4
github
7 месяцев назад

A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.

CVSS3: 5.4
fstec
7 месяцев назад

Уязвимость функции g_unichar_to_utf8() набора библиотек GLib, позволяющая нарушителю вызвать отказ в обслуживании

5.4 Medium

CVSS3