[From nobody Mon Aug 31 15:49:10 2026
Received: (at 1141316-close) by bugs.debian.org; 31 Aug 2026 14:47:22 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-113.6 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FOURLA,
 FVGT_m_MULTI_ODD,HAS_BUG_NUMBER,MD5_SHA1_SUM,PDS_BTC_ID,PGPSIGNATURE,
 SPF_HELO_PASS,SPF_PASS,USER_IN_DKIM_WELCOMELIST autolearn=ham
 autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 85; hammy, 150; neutral, 394; spammy,
 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK,
 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--UD:debian.tar.xz,
 0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo
Return-path: &lt;envelope@ftp-master.debian.org&gt;
Received: from mailly.debian.org ([2001:41b8:202:deb:6564:a62:52c3:4b72]:47920)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1x13IA-007XQD-2A for 1141316-close@bugs.debian.org;
 Mon, 31 Aug 2026 14:47:22 +0000
Received: via submission
 from C=NA, ST=NA, L=Ankh Morpork, O=Debian SMTP, OU=Debian SMTP CA,
 CN=fasolo.debian.org, EMAIL=hostmaster@fasolo.debian.org (verified)
 by mailly.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1x13I9-007xms-0s for 1141316-close@bugs.debian.org;
 Mon, 31 Aug 2026 14:47:21 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
 d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
 Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
 :Content-Description:In-Reply-To:References;
 bh=a/mBeQt85P+/OZy3NYSHW27FSTysl51aAOzcSEuiFoA=; b=pDpl/9jkSbRFyfBUUBnX594z76
 n6dg/KCahHYI7/IZJM59AnZfC7Z7U6GhXKld1REi2saQ4aBSnW66Ler3ZNZ6bo1XYQPtIPjPGdTQi
 slZFCvToyrUqOTUfOa2VAht8Z5UCULS9QXy/wAMnZTQVCTJWcvT4MW0GyX+Pmt2R2Hk5L4PaHoOcA
 Ol/LmDAqNyzHGODOloy0r34lKzgK/sShDQ55jkUYpkocMJrG3ni7vMX4HzixfA+xrW6PSVnwuWQ4n
 UpVl8g1WNoJBCjOfiEqYOlUJiN2q8Ncvh3IJWYnkIaCdqxTTNgVB0Bzj2T4dtdcP99zl0e2Fr1hM/
 FfMvNG/w==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
 (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1x13I8-00000005McG-1by5; Mon, 31 Aug 2026 14:47:20 +0000
From: Debian FTP Masters &lt;ftpmaster@ftp-master.debian.org&gt;
Reply-To: Simon McVittie &lt;smcv@debian.org&gt;
To: 1141316-close@bugs.debian.org
X-DAK: dak process-policy
X-Debian: DAK
X-Debian-Package: glib2.0
Debian: DAK
Debian-Changes: glib2.0_2.84.4-3~deb13u5_source.changes
Debian-Source: glib2.0
Debian-Version: 2.84.4-3~deb13u5
Debian-Architecture: source
Debian-Suite: proposed-updates
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#1141316: fixed in glib2.0 2.84.4-3~deb13u5
Content-Type: multipart/signed; micalg=&quot;pgp-sha256&quot;;
 protocol=&quot;application/pgp-signature&quot;;
 boundary=&quot;===============1406820261355350412==&quot;
Message-Id: &lt;E1x13I8-00000005McG-1by5@fasolo.debian.org&gt;
Date: Mon, 31 Aug 2026 14:47:20 +0000

--===============1406820261355350412==
Content-Type: text/plain; charset=&quot;utf-8&quot;
Content-Transfer-Encoding: quoted-printable

Source: glib2.0
Source-Version: 2.84.4-3~deb13u5
Done: Simon McVittie &lt;smcv@debian.org&gt;

We believe that the bug you reported is fixed in the latest version of
glib2.0, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1141316@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon McVittie &lt;smcv@debian.org&gt; (supplier of updated glib2.0 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 23 Aug 2026 15:20:28 +0100
Source: glib2.0
Architecture: source
Version: 2.84.4-3~deb13u5
Distribution: trixie
Urgency: medium
Maintainer: Debian GNOME Maintainers &lt;pkg-gnome-maintainers@lists.alioth.debi=
an.org&gt;
Changed-By: Simon McVittie &lt;smcv@debian.org&gt;
Closes: 1141316 1142717 1142835
Changes:
 glib2.0 (2.84.4-3~deb13u5) trixie; urgency=3Dmedium
 .
   * Add patches from upstream 2.89.x to fix parsing of XDG MIME magic
     datafiles
     - d/p/CVE-2026-16118/xdgmime-Check-if-caches-are-set-before-dumping-them=
.patch:
       Fix a crash when running tests on a minimal system
     - d/p/CVE-2026-16118/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimem=
agic.c.patch:
       Fix an out-of-bounds write if parsing attacker-controlled MIME-magic
       data. This is unlikely to be exploitable in practice, because an
       attacker with write access to $XDG_DATA_HOME/mime/magic is likely
       to have other ways to cause arbitrary code execution.
       (CVE-2026-16118, glib#3992 upstream, Closes: #1142717)
 .
 glib2.0 (2.84.4-3~deb13u4) trixie; urgency=3Dmedium
 .
   * Edit previous changelog entry to correlate CVE fixes with upstream
     bug numbers and releases
   * Add patches from upstream 2.86.5 to fix out-of-bounds accesses:
     - d/p/gvariant-Fix-an-off-by-one-error-in-an-offset-comparison.patch:
       Fix a potential out of bounds read by 1 byte
       (CVE-2026-58010, glib#3915 upstream)
     - d/p/gmarkup-Fix-potential-one-byte-overread-in-g_markup_escap.patch:
       Fix a potential out of bounds read by 1 byte when escaping text that
       is not valid UTF-8
       (not considered to be a vulnerability, glib#3916 upstream)
     - d/p/gdatetime-Factor-out-a-couple-of-magic-constants.patch,
       d/p/gdatetime-Add-missing-range-validation-to-g_date_time_add.patch:
       Fix an out of bounds read by up to 2 bytes after parsing an
       out-of-range date
       (CVE-2026-58011, glib#3917 upstream)
     - d/p/gregex-Fix-case-changing-substitutions-with-G_REGEX_RAW.patch:
       Fix a potential buffer overflow when changing the case of an incomplete
       UTF-8 sequence while using G_REGEX_RAW
       (CVE-2026-58012, glib#3918 upstream)
     - d/p/gregex-Fix-use-of-wrong-option-flags-set-for-checking-for.patch,
       d/p/gregex-Rename-the-compile_opts-members-to-clarify-their-t.patch:
       Fix an out-of-bounds read when g_regex_split_full() acts on
       invalid UTF-8
       (not considered to be a vulnerability, glib#3919 upstream)
   * Add patches from upstream 2.88.1 to fix several issues that were reported
     as potential security vulnerabilities:
     - d/p/giochannel-Fix-memcmp-off-the-end-of-the-buffer-with-long.patch:
       Fix out-of-bounds read if a GIOChannel is configured with a long
       line-terminator
       (CVE-2026-58013, glib#3825 upstream)
     - d/p/gkeyfile-Fix-a-one-byte-heap-under-read-with-g_key_file_g.patch:
       Fix out-of-bounds read if a list of locale-dependent strings in a
       GKeyFile is empty
       (CVE-2026-58014, glib#3930 upstream)
     - d/p/gdbusmessage-Fix-types-of-integer-arithmetic-in-message-l.patch:
       Fix an integer overflow that could lead to accepting overly large
       messages on peer-to-peer D-Bus connections
       (no CVE ID, glib#3933 upstream)
     - d/p/gdbusauthmechanismsha1-Validate-cookie-context.patch,
       d/p/gdbusauthmechanismsha1-Improve-validation-of-cookie-ID.patch,
       d/p/gdbusauthmechanism-Expose-client-reject-reason-as-a-new-v.patch,
       d/p/tests-Add-a-unit-test-for-GDBusAuthMechanismSha1-cookie-c.patch:
       Prevent path traversal and file-content disclosure if a D-Bus client
       connects to a malicious peer-to-peer D-Bus server
       (CVE-2026-58015, glib#3931 upstream)
   * Add patch from upstream 2.88.3 fixing a possible denial of service:
     - d/p/gdbusauth-Limit-length-of-lines-read-from-client.patch:
       Fix resource exhaustion if a malicious client can contact a
       GDBusServer
       (CVE-2026-15588, glib#3985 upstream, Closes: #1142835)
   * Add patches from upstream 2.89.0 to harden D-Bus introspection parsing
     - d/p/gdbusintrospection-Add-some-assertions-before-array-deref.patch,
       d/p/tests-Improve-D-Bus-introspection-test-paths.patch,
       d/p/gdbusintrospection-Fix-XML-parser-state-handling-for-node.patch,
       d/p/fuzzing-Add-a-fuzz-test-for-g_dbus_node_info_new_for_xml.patch:
       Avoid a possible integer underflow if parsing malformed D-Bus
       introspection XML sent by a malicious service
       (glib#3932 upstream, CVE-2026-58016, Closes: #1141316)
   * d/salsa-ci.yml: Disable uscan job as not relevant to this stable branch
Checksums-Sha1:
 02513a8ebbd960c5029e900fafccfe8ea93c8c4f 5294 glib2.0_2.84.4-3~deb13u5.dsc
 6d92bf8dffbeee2369394a9f40a67f8fb71b478c 172260 glib2.0_2.84.4-3~deb13u5.deb=
ian.tar.xz
 9b353f9d539cfed5d37a00add9f33829a35063fb 15145332 glib2.0_2.84.4-3~deb13u5.g=
it.tar.xz
 8855a2e8cea6ab6fb2aa6d69cb891ed56dd04790 17696 glib2.0_2.84.4-3~deb13u5_sour=
ce.buildinfo
Checksums-Sha256:
 2587beb2f5b90511d0c88a7595c1d3b3ea7a5b7e6582713ecae3713864012858 5294 glib2.=
0_2.84.4-3~deb13u5.dsc
 d8e3603c3780d2cc883d762cf81db9199d8c4c492a82a1a791c117a6d402dbeb 172260 glib=
2.0_2.84.4-3~deb13u5.debian.tar.xz
 568239a3a604022dec493408d0fc10f165639dd19a1eb20f8b01634ee0ce19bc 15145332 gl=
ib2.0_2.84.4-3~deb13u5.git.tar.xz
 8daca739c81b87175322561351976ae779c7e2764982c9cb32949ccf9c881339 17696 glib2=
.0_2.84.4-3~deb13u5_source.buildinfo
Files:
 d257f9927ee86ee1be6df1acea8c9efa 5294 libs optional glib2.0_2.84.4-3~deb13u5=
.dsc
 3465d9f4fbaee31d4d9bf933b3ad43ed 172260 libs optional glib2.0_2.84.4-3~deb13=
u5.debian.tar.xz
 9b23023f29becc2b6b956a29d32bd55c 15145332 libs optional glib2.0_2.84.4-3~deb=
13u5.git.tar.xz
 83e336a108cd04d0d64352d6efb7fde4 17696 libs optional glib2.0_2.84.4-3~deb13u=
5_source.buildinfo
Git-Tag-Info: tag=3Deb1c6804e6bb2fa38dec94d4037e3b30a55fbf5d fp=3D7a073ad1ae6=
94fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie &lt;smcv@debian.org&gt;

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqLMEoACgkQYG0ITkaD
wHnzZg//bOMScFzHsYV/2U6cdqWd3BgRMvfn/rJMCEwxQXTrUsAmn/DHSsHqlgxs
mY5Qk+PfHwcPfF3rKiRCM5VZs4WoWwd611EAyr57viNhT4RRMOqEbw393f63CSMn
MlmRu208MvW6S/gsJfol+tIZUFwaSkZX6Q0cS90SkQIPDuWQZFq+VsfRdy+y785x
gkkGyeB1U/rQaeVLVu6jTOvPQ36yY9bg8xPfwm0Zf5Jrjy2rK9PZB7SoFcx3kPkL
bKHIf9gsrtiGBb6p8knovwEUXF/6ngNRlBvyN4AaGAe9gXArHfTe9wiYSup0dd0h
/p5mrzE/2WgDrdIEqbBMSUm5iRqIcpvhkSmCDZ3/GUPHPxubiGJBFDz8nDAvjwMm
L05T9QNq4Q6aLtKqsf29+QTvIpMtqSgsX7Kua+llyTOrpKCkWiXijXDOC0hX8m4M
Q7F1uXh59fHMQLn5TexLxR/DyKg80TO9bpUa1Be1vNNhQ854I6arINKngHT08M0a
MAbtlO/DAjndPSspIVrxKPcv6kqAP4SZRZgcrwoY6Q2t6n7RKyi5kONjhYal0Ik8
JJH/onvUo2gV65Oq2U7qVQGiHlUHDi2qStKakY67BnXW3qD5I46TYZrytr1y3iNa
CibI1nztFPKagzevQALSAPr2JybeKIMf1o1NT9TIBcHI9J37IoE=3D
=3DB3I3
-----END PGP SIGNATURE-----


--===============1406820261355350412==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCapWT+AAKCRCb9qggYcy5
ITwFAQC16tjIZGmQXWzrEcHxlyWHDp7f4Pyxh8HZKmznnjPtnwD9Ey8GgRtDU2oD
lacJlczThddj6XVHTSn4asfkOkriHgc=
=hFgZ
-----END PGP SIGNATURE-----

--===============1406820261355350412==--
]