{
  "threat_severity" : "Important",
  "public_date" : "2026-04-08T00:00:00Z",
  "bugzilla" : {
    "description" : "glib: integer underflow in gio/gdbusintrospection.c via \"g_dbus_node_info_new_for_xml\"",
    "id" : "2492257",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2492257"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-191",
  "details" : [ "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.", "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service." ],
  "statement" : "Any applications processing D-Bus introspection XML input from untrusted sources with g_dbus_node_info_new_for_xml() are vulnerable to this issue. In GLib itself, the gdbus command line tool is the primary vector for local exploitation. However, other applications using the vulnerable function may process untrusted input in a way that allows a remote attacker to trigger this flaw. This vulnerability can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service. As this vulnerability allows a remote attacker to cause a denial of service, it has been rated with an important severity.",
  "acknowledgement" : "Red Hat would like to thank linhlhq for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:42063",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "glib2-0:2.80.4-12.el10_2.14"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-08-06T00:00:00Z",
    "advisory" : "RHSA-2026:51185",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "glib2-0:2.80.4-4.el10_0.10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
    "release_date" : "2026-08-06T00:00:00Z",
    "advisory" : "RHSA-2026:51183",
    "cpe" : "cpe:/o:redhat:rhel_els:7",
    "package" : "glib2-0:2.56.1-13.el7_9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-08-03T00:00:00Z",
    "advisory" : "RHSA-2026:49512",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8::crb",
    "package" : "mingw-glib2-0:2.70.1-9.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:42090",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8",
    "package" : "glib2-0:2.56.4-170.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support",
    "release_date" : "2026-08-06T00:00:00Z",
    "advisory" : "RHSA-2026:51184",
    "cpe" : "cpe:/o:redhat:rhel_aus:8.4",
    "package" : "glib2-0:2.56.4-10.el8_4.6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-08-06T00:00:00Z",
    "advisory" : "RHSA-2026:51184",
    "cpe" : "cpe:/o:redhat:rhel_eus_long_life:8.4",
    "package" : "glib2-0:2.56.4-10.el8_4.6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
    "release_date" : "2026-08-06T00:00:00Z",
    "advisory" : "RHSA-2026:51181",
    "cpe" : "cpe:/o:redhat:rhel_aus:8.6",
    "package" : "glib2-0:2.56.4-158.el8_6.6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On",
    "release_date" : "2026-08-06T00:00:00Z",
    "advisory" : "RHSA-2026:51181",
    "cpe" : "cpe:/o:redhat:rhel_eus_long_life:8.6",
    "package" : "glib2-0:2.56.4-158.el8_6.6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Telecommunications Update Service",
    "release_date" : "2026-08-06T00:00:00Z",
    "advisory" : "RHSA-2026:51182",
    "cpe" : "cpe:/o:redhat:rhel_tus:8.8",
    "package" : "glib2-0:2.56.4-165.el8_8.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions",
    "release_date" : "2026-08-06T00:00:00Z",
    "advisory" : "RHSA-2026:51182",
    "cpe" : "cpe:/o:redhat:rhel_e4s:8.8",
    "package" : "glib2-0:2.56.4-165.el8_8.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:42089",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "glib2-0:2.68.4-19.el9_8.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-20T00:00:00Z",
    "advisory" : "RHSA-2026:42089",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "glib2-0:2.68.4-19.el9_8.2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2026-08-06T00:00:00Z",
    "advisory" : "RHSA-2026:51176",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "glib2-0:2.68.4-7.el9_2.6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-08-06T00:00:00Z",
    "advisory" : "RHSA-2026:51177",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "glib2-0:2.68.4-14.el9_4.7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-08-06T00:00:00Z",
    "advisory" : "RHSA-2026:51175",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "glib2-0:2.68.4-16.el9_6.6"
  }, {
    "product_name" : "Red Hat Discovery 2",
    "release_date" : "2026-07-27T00:00:00Z",
    "advisory" : "RHSA-2026:46836",
    "cpe" : "cpe:/a:redhat:discovery:2::el9",
    "package" : "discovery/discovery-server-rhel9:1784821670"
  }, {
    "product_name" : "Red Hat Discovery 2",
    "release_date" : "2026-07-27T00:00:00Z",
    "advisory" : "RHSA-2026:46836",
    "cpe" : "cpe:/a:redhat:discovery:2::el9",
    "package" : "discovery/discovery-ui-rhel9:1784821750"
  }, {
    "product_name" : "Red Hat Insights proxy 1.5",
    "release_date" : "2026-08-11T00:00:00Z",
    "advisory" : "RHSA-2026:53371",
    "cpe" : "cpe:/a:redhat:insights_proxy:1.5::el9",
    "package" : "insights-proxy/insights-proxy-container-rhel9:1786433656"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44481",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/cds-kubernetes-rhel9:1784794818"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44481",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/cds-rhel9:1784794778"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44481",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/haproxy-rhel9:1784795112"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44481",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/installer-rhel9:1784794289"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44481",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-rhel9:1784795076"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/cds-kubernetes-tp-rhel9:1787241211"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/installer-tp-rhel9:1787135742"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-tp-rhel9:1787241260"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Affected",
    "package_name" : "mingw-glib2",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Will not fix",
    "package_name" : "glib2",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Will not fix",
    "package_name" : "mingw-glib2",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "fix_state" : "Not affected",
    "package_name" : "glib2",
    "cpe" : "cpe:/a:redhat:hummingbird:1"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-58016\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-58016\nhttps://gitlab.gnome.org/GNOME/glib/-/issues/3932" ],
  "name" : "CVE-2026-58016",
  "mitigation" : {
    "value" : "To mitigate this vulnerability, implement input validation to sanitize untrusted D-Bus introspection XML, specifically rejecting malformed structures such as <node> elements improperly nested within <method>, <signal>, <property> or <arg> elements before calling g_dbus_node_info_new_for_xml(). Alternatively, restricting the application to only process XML input from trusted, authenticated sources will completely neutralize this issue.",
    "lang" : "en:us"
  },
  "csaw" : false
}