#1138235 glib-networking: CVE-2026-10028

Package:
src:glib-networking
Source:
src:glib-networking
Submitter:
Salvatore Bonaccorso
Date:
2026-09-20 07:43:03 UTC
Severity:
normal
Tags:
#1138235#5
Date:
2026-05-29 18:55:01 UTC
From:
To:
Hi,

The following vulnerability was published for glib-networking.

CVE-2026-10028[0]:
| A flaw was found in glib-networking. A remote attacker can exploit
| this vulnerability by presenting a specially crafted certificate
| chain to an application that uses glib-networking with the GnuTLS
| backend enabled and performs certificate verification. This crafted
| chain, which contains circular issuer relationships, can cause an
| infinite loop during certificate verification. The unbounded
| traversal consumes excessive CPU resources, leading to a denial of
| service for the affected process or worker.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-10028
https://www.cve.org/CVERecord?id=CVE-2026-10028
[1] https://gitlab.gnome.org/GNOME/glib-networking/-/work_items/231

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1138235#12
Date:
2026-09-19 11:05:58 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
glib-networking, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1138235@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jeremy Bícha <jbicha@ubuntu.com> (supplier of updated glib-networking package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 19 Sep 2026 12:30:11 +0200
Source: glib-networking
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 2.90.0-1
Distribution: unstable
Urgency: high
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Jeremy Bícha <jbicha@ubuntu.com>
Closes: 1138235
Changes:
 glib-networking (2.90.0-1) unstable; urgency=high
 .
   * New upstream release
     - SECURITY UPDATE - Fix infinite loop in certificate verification
       - CVE-2026-10028 (Closes: #1138235)
     - SECURITY UPDATE - Fix out-of-bounds read through
       tls/openssl/gtlsclientconnection-openssl.c via
       g_tls_client_connection_openssl_get_property()
       - CVE-2026-2574
     - SECURITY UPDATE - Fix out-of-bounds read through
       tls/openssl/gtlsclientconnection-openssl.c via
       g_tls_client_connection_openssl_get_property()
       - CVE-2026-60018
     - SECURITY UPDATE - Fix uninitialized memory dereference through
       g_tls/openssl/gtlscbio.c via
       g_tls_bio_new_from_iostream() and g_tls_bio_new_from_datagram_based()
       - CVE-2026-60019
   * Opt into Salsa CI
   * Update debhelper compat to 14
   * Update Standards Version to 4.7.4
   * Misc packaging updates
Checksums-Sha1:
 f5d9ceab3ff619db8438bf3bc69e725acb129286 2411 glib-networking_2.90.0-1.dsc
 275c658bb2c27bd8a03e0b3142dd2a203dcbcb81 290168 glib-networking_2.90.0.orig.tar.xz
 54a6437df46191cf0852a2f82e83ff5354fae690 12740 glib-networking_2.90.0-1.debian.tar.xz
 6a8f0a24e8aa32301fdd55a7ff5902041471c759 11432 glib-networking_2.90.0-1_source.buildinfo
Checksums-Sha256:
 3846cfbf8853c399f90fbe78b205c486e430fef12bb0cb295755d789d5332f9f 2411 glib-networking_2.90.0-1.dsc
 83a75e3d9c36b66ee86d3281c2fc997816101968a5126ba322b2acb9a74dd8c0 290168 glib-networking_2.90.0.orig.tar.xz
 a8d8fbdfc51a2f21c6aea1bf651ffa9bb787380051672d3e4fd28435c7c8e44c 12740 glib-networking_2.90.0-1.debian.tar.xz
 816394e00963fbce08240cd76a761f139fbef66e24ddd0c43c7e382512444332 11432 glib-networking_2.90.0-1_source.buildinfo
Files:
 8d194d12467d3ba9adf0256f63a99d40 2411 libs optional glib-networking_2.90.0-1.dsc
 87d6ce1d1dab10fb20ea783ca55e40a1 290168 libs optional glib-networking_2.90.0.orig.tar.xz
 edcfd467f8f92be6ee34484dc82f3e84 12740 libs optional glib-networking_2.90.0-1.debian.tar.xz
 8ecdbb3107f03a4fdb9340bc4dc38c48 11432 libs optional glib-networking_2.90.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmquZqEACgkQ5mx3Wuv+
bH2BhRAA2KmkJ2ik5foVa6clLBPqKN3B00jssbc0zMmInT4FZbiWHdor9lhDTpRG
igU+xeE2p+kq0j7HypllKhiyF5gqa/3SvM+jyMtEjvsREDqfMRtzHaqp5xJqoizX
cdM+Oj+9UVdUS2NCO01V63SY26khwwQbkP2Izu1r9ymFKJCcmgwMwqaFS0jyexN5
9slVoHog7N00lxkIGCkLa5+82po6ciBqLNcEoKPZrWZoZd5e9lEz3AfKMFmhjAgc
y7jWX6RfiJnJTNl7eqMZVVoS1snAEzUCgjEgitIQp0nlZwosM52KYMTJKwMaunlO
Twpd0wMqD/bUSdsM2eFbZtuls/h2ZWTBbW9+hBylrfFUUVuMLScTqkVTpkDDkiOy
T+3ItzLlt+0pPa7hBt5CbYM4VoIiCLhC1L5DOQIPcwqiTbAdcZd3NKSAM761aoda
FNJwwxo/fXFbP31Xt0Y2UfDAuvkYQlbOBPy6J3U0uhSymopqlhlyXyb+zQcTz5Gw
ViLx3QgsIp5qOykNM3PkxeJFE1IT+HHUeThs8BURQqJGjx2chCT95aK75kV8eivB
W6gdIAwOwebShGc23fm1dlzaPcvoRvfy5Xg3/IaezFFvS2vEMB0p1YjuRAC90Tmq
KCsqDmYK1vId08TpVKhQwIbPEBRMx58Hu7kl18EOahhdO4E/Yiw=
=EBzA
-----END PGP SIGNATURE-----

#1138235#17
Date:
2026-09-20 07:42:05 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
glib-networking, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1138235@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jeremy Bícha <jbicha@ubuntu.com> (supplier of updated glib-networking package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 20 Sep 2026 09:18:39 +0200
Source: glib-networking
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 2.90.0-2
Distribution: unstable
Urgency: high
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Jeremy Bícha <jbicha@ubuntu.com>
Closes: 1138235
Changes:
 glib-networking (2.90.0-2) unstable; urgency=high
 .
   * New upstream release
     - SECURITY UPDATE - Fix infinite loop in certificate verification
       - CVE-2026-10028 (Closes: #1138235)
     - SECURITY UPDATE - Fix out-of-bounds read through
       tls/openssl/gtlsclientconnection-openssl.c via
       g_tls_client_connection_openssl_get_property()
       - CVE-2026-2574
     - SECURITY UPDATE - Fix out-of-bounds read through
       tls/openssl/gtlsclientconnection-openssl.c via
       g_tls_client_connection_openssl_get_property()
       - CVE-2025-60018
     - SECURITY UPDATE - Fix uninitialized memory dereference through
       g_tls/openssl/gtlscbio.c via
       g_tls_bio_new_from_iostream() and g_tls_bio_new_from_datagram_based()
       - CVE-2025-60019
   * Opt into Salsa CI
   * Update debhelper compat to 14
   * Update Standards Version to 4.7.4
   * Misc packaging updates
Checksums-Sha1:
 6fce2703eb3f49a8f5c3ab4c5223dfa6afcf6040 2411 glib-networking_2.90.0-2.dsc
 275c658bb2c27bd8a03e0b3142dd2a203dcbcb81 290168 glib-networking_2.90.0.orig.tar.xz
 744ac9e9d96b4fb3560bdb9c5e5837d21173e255 12736 glib-networking_2.90.0-2.debian.tar.xz
 1dc4ce599cee2288da5781460b21efbcf6a93779 11432 glib-networking_2.90.0-2_source.buildinfo
Checksums-Sha256:
 8d4ee18104dfb4538cb3e4eac285a4c7b73cc9d87fa8352c2c9bb46537319d53 2411 glib-networking_2.90.0-2.dsc
 83a75e3d9c36b66ee86d3281c2fc997816101968a5126ba322b2acb9a74dd8c0 290168 glib-networking_2.90.0.orig.tar.xz
 2935ad06c9c679b47b4338ff062922a41823ab1cf92eaa8d907f6c7ec727a27c 12736 glib-networking_2.90.0-2.debian.tar.xz
 4d2ad1cea750ee031e76ce47c52ad880a0e849ada8830e51ed57f5847b3a40d6 11432 glib-networking_2.90.0-2_source.buildinfo
Files:
 5f385e6bebb851b1d9622eed67978eb9 2411 libs optional glib-networking_2.90.0-2.dsc
 87d6ce1d1dab10fb20ea783ca55e40a1 290168 libs optional glib-networking_2.90.0.orig.tar.xz
 ee5f431d7ae854241f9959dca70b0b3c 12736 libs optional glib-networking_2.90.0-2.debian.tar.xz
 a78b34627754de3dd7ba0d38f4db0857 11432 libs optional glib-networking_2.90.0-2_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmqviOIACgkQ5mx3Wuv+
bH2zvRAA4tBI7/aYyGW4TdtVqNWaCF1hset5TGW4uz94sq5dvtatK6KIFYerHXi7
hT2v7vs2nNAIbOjZlnBDjEWsGHD/F63x9mSXcUgw4BZBvXrdnCSqX6vtfEgJ3z4F
4TNhCPNsxdG1kicrvyiHi5QRcntyI8eyJly4JBJ/xWpQGcZTpf7+nSRWLS0UiUKC
s4crRMktqYg8/ufShDjfILO2cXX0zC6s48Tkfn5ScOAYBs0ZKWZ4GYD323JW52wF
mMtxpf3Onsqk81fGtMnBD1TJ8+xZL4vTCIL8xoGrHCnTSa5urIHmZvMiddbrjvrm
6LcoKn+8TI2FPgoJg03YciH2YdZ2QQSJu4+iQjEfy7nlRn/HLRawSPGeFycW0fL/
9O2XuG+nd1FPC1dfreIdlwBh7TfCNZCGAXLzvs9cPQql+fIGVbyRUuJNR4435EzW
8XInRRKIr1ko2pMI/xnN5GyvBY+3Ojhu3usEEhfnPLx6yov3FplASxEfoPaJKaaO
tj2mUNdb5HjL03hoKdlqg9T1nwNWo7Hn7Q4w0q6bFKZaXxx6wYovzZKnyF/k3nbc
t/b+sVuSNLDiDVGcfTwd5drzOwYX/fggRDsPw9tAAS53OB43wXfQG575zL18IicR
VXaJLKf7wgWnMNUEd6jE5wQP/RwJ3brh4Nxz4oTF4y71h1etiI8=
=LxRn
-----END PGP SIGNATURE-----