{
  "threat_severity" : "Moderate",
  "public_date" : "2026-03-26T00:00:00Z",
  "bugzilla" : {
    "description" : "glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()",
    "id" : "2492243",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2492243"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-126",
  "details" : [ "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.", "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary." ],
  "statement" : "Any applications calling the `g_variant_is_normal_form()`, `g_variant_get_normal_form()` or `g_variant_byteswap()` functions that process untrusted GVariant data received from D-Bus, network or file are vulnerable to this issue. This flaw can cause an out-of-bounds read of only 1 byte, leading to an information disclosure of only 1 byte and a denial of service when the out-of-bounds read crosses a page boundary. Due to these reasons, this vulnerability has been rated with a moderate severity.",
  "acknowledgement" : "Red Hat would like to thank linhlhq for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-08-19T00:00:00Z",
    "advisory" : "RHSA-2026:57015",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "glib2-0:2.80.4-12.el10_2.21"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-08-03T00:00:00Z",
    "advisory" : "RHSA-2026:49512",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8::crb",
    "package" : "mingw-glib2-0:2.70.1-9.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-08-31T00:00:00Z",
    "advisory" : "RHSA-2026:61766",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8",
    "package" : "glib2-0:2.56.4-177.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-08-17T00:00:00Z",
    "advisory" : "RHSA-2026:55440",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "glib2-0:2.68.4-19.el9_8.9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-08-17T00:00:00Z",
    "advisory" : "RHSA-2026:55440",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "glib2-0:2.68.4-19.el9_8.9"
  }, {
    "product_name" : "Cert Manager support for Red Hat OpenShift release 1.19",
    "release_date" : "2026-09-03T00:00:00Z",
    "advisory" : "RHSA-2026:63135",
    "cpe" : "cpe:/a:redhat:cert_manager:1.19::el9",
    "package" : "cert-manager/cert-manager-operator-rhel9:1788348522"
  }, {
    "product_name" : "Cert Manager support for Red Hat OpenShift release 1.19",
    "release_date" : "2026-09-03T00:00:00Z",
    "advisory" : "RHSA-2026:63138",
    "cpe" : "cpe:/a:redhat:cert_manager:1.19::el9",
    "package" : "cert-manager/jetstack-cert-manager-acmesolver-rhel9:1788348571"
  }, {
    "product_name" : "Cert Manager support for Red Hat OpenShift release 1.19",
    "release_date" : "2026-09-03T00:00:00Z",
    "advisory" : "RHSA-2026:63138",
    "cpe" : "cpe:/a:redhat:cert_manager:1.19::el9",
    "package" : "cert-manager/jetstack-cert-manager-rhel9:1788348571"
  }, {
    "product_name" : "Cert Manager support for Red Hat OpenShift release 1.19",
    "release_date" : "2026-09-03T00:00:00Z",
    "advisory" : "RHSA-2026:63140",
    "cpe" : "cpe:/a:redhat:cert_manager:1.19::el9",
    "package" : "cert-manager/cert-manager-istio-csr-rhel9:1788348594"
  }, {
    "product_name" : "Red Hat Discovery 2",
    "release_date" : "2026-08-31T00:00:00Z",
    "advisory" : "RHSA-2026:61783",
    "cpe" : "cpe:/a:redhat:discovery:2::el9",
    "package" : "discovery/discovery-server-rhel9:1788205779"
  }, {
    "product_name" : "Red Hat Discovery 2",
    "release_date" : "2026-08-31T00:00:00Z",
    "advisory" : "RHSA-2026:61783",
    "cpe" : "cpe:/a:redhat:discovery:2::el9",
    "package" : "discovery/discovery-ui-rhel9:1788206196"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/cds-kubernetes-tp-rhel9:1787241211"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/installer-tp-rhel9:1787135742"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-tp-rhel9:1787241260"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Affected",
    "package_name" : "mingw-glib2",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Will not fix",
    "package_name" : "glib2",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Affected",
    "package_name" : "glib2",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Will not fix",
    "package_name" : "mingw-glib2",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "fix_state" : "Not affected",
    "package_name" : "glib2",
    "cpe" : "cpe:/a:redhat:hummingbird:1"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-58010\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-58010\nhttps://gitlab.gnome.org/GNOME/glib/-/issues/3915" ],
  "name" : "CVE-2026-58010",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}