« List of all CVEs

CVE-2026-58012

Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()

Published: 6/30/2026 Last updated: 6/30/2026 Reserved: 6/26/2026

A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 6.5 Medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Opam packages affected (1)

conf-glib-2

Products affected (10)

Product Vendor Version
GLib GNOME 7.4
Red Hat Enterprise Linux 10 Red Hat Android-10 Android-11 Android-12 Android-12L
Red Hat Enterprise Linux 6 Red Hat 2.2.0.0.0
Red Hat Enterprise Linux 7 Red Hat 4.2.0.2.0
Red Hat Enterprise Linux 8 Red Hat 4.2.0.3.0
Red Hat Hardened Images Red Hat < 10.0.19042.1415
Red Hat Enterprise Linux 9 Red Hat < 10.0.19043.1415
Red Hat Enterprise Linux 10 Red Hat n/a
Red Hat Enterprise Linux 9 Red Hat < 10.0.19041.1415
Red Hat Enterprise Linux 8 Red Hat 4.4.0.2.0

References (3)

Credits (1)