Bug#1142717: glib2.0: CVE-2026-16118

Simon McVittie smcv at debian.org
Fri Jul 24 15:08:18 BST 2026


On Fri, 24 Jul 2026 at 15:37:42 +0200, Salvatore Bonaccorso wrote:
>| A heap-based buffer overflow can be
>| triggered [...] when an attacker-
>| controlled MIME magic file in a user-writable XDG data location
>| (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed

I'm having a hard time thinking of reasons why this would be crossing a 
security boundary: if a program has the ability to write to 
$XDG_DATA_HOME then it's already part of the trusted computing base for 
this user (for example it could configure `systemd --user` to run 
arbitrary code), and I can't think of a reason why it would be desirable 
to let untrusted/sandboxed software write to $XDG_DATA_HOME/mime/magic, 
which would let that software change the rules by which files are 
classified into their MIME types.

(Flatpak apps can export a file into XDG_DATA_HOME/mime/packages, but 
not into .../magic.)

     smcv



More information about the pkg-gnome-maintainers mailing list