« List of all CVEs

CVE-2026-58016

Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"

Published: 6/30/2026 Last updated: 7/23/2026 Reserved: 6/26/2026

A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> or <arg>. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 7.5 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Opam packages affected (1)

conf-glib-2

Products affected (32)

Product Vendor Version
GLib GNOME < 20.2R3-S3
GLib GNOME 2012
Red Hat Enterprise Linux 10 Red Hat < 20.3R3-S1
Red Hat Enterprise Linux 9 Red Hat < 21.1R3
Red Hat Enterprise Linux 9 Red Hat < 21.2R2
Red Hat Enterprise Linux 6 Red Hat >=14.7.0, <14.7.4
Red Hat Enterprise Linux 7 Red Hat >=14.8.0, <14.8.2
Red Hat Hardened Images Red Hat < 80
Red Hat Hardened Images Red Hat < 2.4.6
Red Hat Enterprise Linux 10 Red Hat unspecified
Red Hat Enterprise Linux 8 Red Hat < 2.2.2
Red Hat Enterprise Linux 9 Red Hat < 21.3.1
Red Hat Enterprise Linux 9 Red Hat <= 2020.013.20074
Red Hat Enterprise Linux 6 Red Hat < 2.2.36
Red Hat Enterprise Linux 7 Red Hat < 16.11.5
Red Hat Enterprise Linux 8 Red Hat < 20.4R3
Red Hat Enterprise Linux 10 Red Hat >=14.6, <14.6.5
Red Hat Enterprise Linux 9 Red Hat < 10.0.17763.2686
Red Hat Enterprise Linux 10 Red Hat < publication
Red Hat Enterprise Linux 8 Red Hat firmware version 4.1
Red Hat Enterprise Linux 9 Red Hat < 14.4
Red Hat Enterprise Linux 8 Red Hat < 10.0.17763.2686
Red Hat Update Infrastructure 5 Red Hat < 10.0.19043.1110
Red Hat Update Infrastructure 5 Red Hat < 20.4R3-S3-EVO
Red Hat Update Infrastructure 5 Red Hat < 21.2R2-EVO
Red Hat Update Infrastructure 5 Red Hat < publication
Red Hat Update Infrastructure 5 Red Hat < 6.0.6003.21167
Red Hat Update Infrastructure 5 Red Hat n/a
Red Hat Update Infrastructure 5 Red Hat n/a
Red Hat Update Infrastructure 5 Red Hat < publication
Red Hat Update Infrastructure 5 Red Hat n/a
Red Hat Update Infrastructure 5 Red Hat < publication

References (14)

Credits (2)