Bug#1141316: glib2.0: CVE-2026-58016
Moritz Mühlenhoff
jmm at inutil.org
Thu Jul 2 22:15:56 BST 2026
Source: glib2.0
X-Debbugs-CC: team at security.debian.org
Severity: important
Tags: security
Hi,
The following vulnerability was published for glib2.0.
CVE-2026-58016[0]:
| A flaw was found in GLib. A state confusion issue exists in
| g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file
| when processing malformed D-Bus introspection XML, specifically with
| a <node> element nested within other elements like <method>,
| <signal>, <property> or <arg>. This issue can cause an unsigned
| integer overflow and lead to an out-of-bounds read, resulting in a
| denial of service.
https://gitlab.gnome.org/GNOME/glib/-/work_items/3932
https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5156 (2.89.0)
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-58016
https://www.cve.org/CVERecord?id=CVE-2026-58016
Please adjust the affected versions in the BTS as needed.
More information about the pkg-gnome-maintainers
mailing list