#1141316 glib2.0: CVE-2026-58016

Package:
src:glib2.0
Source:
src:glib2.0
Submitter:
Moritz Mühlenhoff
Date:
2026-08-21 15:17:02 UTC
Severity:
normal
Tags:
#1141316#5
Date:
2026-07-02 21:15:56 UTC
From:
To:
Hi,

The following vulnerability was published for glib2.0.

CVE-2026-58016[0]:
| A flaw was found in GLib. A state confusion issue exists in
| g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file
| when processing malformed D-Bus introspection XML, specifically with
| a <node> element nested within other elements like <method>,
| <signal>, <property> or <arg>. This issue can cause an unsigned
| integer overflow and lead to an out-of-bounds read, resulting in a
| denial of service.

https://gitlab.gnome.org/GNOME/glib/-/work_items/3932
https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5156 (2.89.0)


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-58016
https://www.cve.org/CVERecord?id=CVE-2026-58016

Please adjust the affected versions in the BTS as needed.

#1141316#18
Date:
2026-08-02 16:50:27 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
glib2.0, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1141316@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon McVittie <smcv@debian.org> (supplier of updated glib2.0 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 02 Aug 2026 17:22:30 +0100
Source: glib2.0
Architecture: source
Version: 2.88.3-2
Distribution: unstable
Urgency: medium
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Closes: 1141316
Changes:
 glib2.0 (2.88.3-2) unstable; urgency=medium
 .
   * Backport patches from 2.89.0 to harden D-Bus introspection parsing
     - d/p/gdbusintrospection-Add-some-assertions-before-array-deref.patch,
       d/p/tests-Improve-D-Bus-introspection-test-paths.patch,
       d/p/gdbusintrospection-Fix-XML-parser-state-handling-for-node.patch,
       d/p/fuzzing-Add-a-fuzz-test-for-g_dbus_node_info_new_for_xml.patch:
       Avoid a possible integer underflow if parsing malformed D-Bus
       introspection XML sent by a malicious service
       (glib#3932 upstream, CVE-2026-58016, Closes: #1141316)
   * d/tests/1065022-futureproofing: Make the test pass more reliably,
     by ensuring that user-session-migration gets removed rather than
     making libglib2.0-0t64 be reinstalled
Checksums-Sha1:
 bf8c4ac06a9768582eff50dab4f29167ef919fed 5091 glib2.0_2.88.3-2.dsc
 2a94b1e955cb1d31060f7240e8a7638c4519508e 145756 glib2.0_2.88.3-2.debian.tar.xz
 dff7f5b14b7cf6f15df098165b5d865ae224238c 15779444 glib2.0_2.88.3-2.git.tar.xz
 40080502c431a3abaf23569f7a600bdc40973aa7 17556 glib2.0_2.88.3-2_source.buildinfo
Checksums-Sha256:
 adc31bd6d4cb8684ca244c002465ea86d2a5be7f115e1ac6aeb48699f174bed6 5091 glib2.0_2.88.3-2.dsc
 56cd728ff13c1d5b39ab9cf8001df330b1858054588e8490b34bff24a68b2010 145756 glib2.0_2.88.3-2.debian.tar.xz
 9a25b1ee4914d57ee04f143239b23486c04df60165db9603b961583ef0ab9da4 15779444 glib2.0_2.88.3-2.git.tar.xz
 5b5b7a465fba88fbce71f291c509b11b956058e95fe97ef08a80548c1002e83c 17556 glib2.0_2.88.3-2_source.buildinfo
Files:
 c777505340d1585e560c7d32e80dc0ab 5091 libs optional glib2.0_2.88.3-2.dsc
 491231247db8881178eff0807bf25431 145756 libs optional glib2.0_2.88.3-2.debian.tar.xz
 7cece885a14f39308f253b27d6eee951 15779444 libs None glib2.0_2.88.3-2.git.tar.xz
 846a668d2b31cb74fd555617b7dffdea 17556 libs optional glib2.0_2.88.3-2_source.buildinfo
Git-Tag-Info: tag=054c63f5a9a53068744420901b2bd3ff3a3142d8 fp=7a073ad1ae694fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie <smcv@debian.org>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmpvcAUACgkQYG0ITkaD
wHnJ6RAAhBkvN7y95tekj8e1JQgcocvVo7NoafV0svkHeuZ78GPajJXNEcT325gH
iYM8CkLSf/RPJJyYjQWHkdqPL7ToUSXoNBMRylkilk2ys5j9v75/ppIw/BOVHOOr
5ty8uJBJFR5G+8B5GjkCBOHjzwfvpmR7Og/uopFFDGICBvsSrUksYL+aEn2LuaS9
+1QG/eSiE0xHj397rv2MruVEZYkwvH4INlySEHWDMq4BdZ9TpOEOhsb5oi7qKswD
lhmMHjhiPEAQix4BAfZx7IcZfjy85+yG7x9whix90nvwKeIbqXrIXgljnCpKiISe
jp3rRXJmwaFgGRPUey5sW5J/TvPQ6B4aMWd532qXVREI87sUMYvWXNkm2ow09u4U
evGrlaJjp57QC2BcONX0In7sN6esDTYOAMhH1rHlIhs0S+jLHiIpztUem9sV2hb+
Ucw7UONGGhcob+9JzeruQT15W3vBm4c8QhWhuSA3+ytEw1ERKZmWL7QBoNQWZFqm
3RKaJjMWWHMlIFp5q1n6Plrk0iiwClRfDLg4gTwz1GXcYrVRa36I2t67UcK4I5if
x0IbSZg79ES5V0D5+BU+vSxOw1HACpC+WKfNc40xoun4GpfFLfiOYGf5sRGUezll
98iziz4YvWGwP6+Ty0VpWDztjwuNElscz0xPw2OUXVBhxrqpj04=
=JvEb
-----END PGP SIGNATURE-----

#1141316#23
Date:
2026-08-21 15:14:28 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
glib2.0, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1141316@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jeremy Bícha <jbicha@ubuntu.com> (supplier of updated glib2.0 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 21 Aug 2026 16:37:11 +0200
Source: glib2.0
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 2.89.3-5
Distribution: unstable
Urgency: medium
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Jeremy Bícha <jbicha@ubuntu.com>
Closes: 1141316 1142717 1142835
Changes:
 glib2.0 (2.89.3-5) unstable; urgency=medium
 .
   * Release to unstable
 .
 glib2.0 (2.89.3-4) experimental; urgency=medium
 .
   * Merge from unstable
     - d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,
       d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:
       Add patches from upstream (to be released in 2.89.4) to address
       an out-of-bounds write if parsing a crafted XDG MIME magic file,
       and fix a related test failure on minimal systems
       (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)
   * d/p/workarounds: Mark memory-monitor-psi tests as flaky
     (Mitigates: #1143197, #1143241)
 .
 glib2.0 (2.89.3-3) experimental; urgency=medium
 .
   [ Simon McVittie ]
   * Merge packaging from unstable
     - d/tests/1065022-futureproofing: Make the test pass more reliably,
       by ensuring that user-session-migration gets removed rather than
       making libglib2.0-0t64 be reinstalled
   * Drop patches added by 2.88.3-2, already part of 2.89.x
 .
 glib2.0 (2.89.3-2) experimental; urgency=medium
 .
   * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:
     Add patch from upstream to fix autopkgtest regression
   * d/changelog: Mention CVE-2026-15588, CVE-2026-58016 in the appropriate
     previous changelog entry
 .
 glib2.0 (2.89.3-1) experimental; urgency=medium
 .
   * New upstream release
   * debian/libglib2.0-0t64.symbols: Add new symbols
 .
 glib2.0 (2.89.2-1) experimental; urgency=medium
 .
   * New upstream release
     - Fixes possible integer underflow when parsing D-Bus introspection XML
       (CVE-2026-58016, Closes: #1141316)
     - Fixes resource exhaustion if a malicious client can contact a GDBusServer
       (CVE-2026-15588, Closes: #1142835)
   * d/p: Refresh patches
   * d/libglib2.0-0t64.symbols: Add new symbol
Checksums-Sha1:
 92f5c3d181b04bdf2bd126fd09f1c7d47d33d99b 4809 glib2.0_2.89.3-5.dsc
 af3872a6ab841fbd4618d11dcda02317a2fea995 145180 glib2.0_2.89.3-5.debian.tar.xz
 c14291048b10042d3ac029149f7e2baff3e6fac3 11637 glib2.0_2.89.3-5_source.buildinfo
Checksums-Sha256:
 d051d1b8f572ce65c8959d97d6433c2c685c6374fbf52a71d11fbadfe210e701 4809 glib2.0_2.89.3-5.dsc
 0fe2c3c9bf1a90376edb6ec3e4e602190b9df72c987cf3f3961e0a132d4aa5fb 145180 glib2.0_2.89.3-5.debian.tar.xz
 f57785267e300de810197e17b7dea6a05c60ee2aa8aa39ef041c0ea105c8208b 11637 glib2.0_2.89.3-5_source.buildinfo
Files:
 51909061d0431c875d197b9aa150a732 4809 libs optional glib2.0_2.89.3-5.dsc
 f7eb67b8b062f653390d1b9ca48502f8 145180 libs optional glib2.0_2.89.3-5.debian.tar.xz
 1677d300f3671162f2584bca30d78f2f 11637 libs optional glib2.0_2.89.3-5_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmqIYuYACgkQ5mx3Wuv+
bH1LlBAA0sAu2oTrdbp5reAEPTYrtgzuEM3RZvfZZ9PFjyXnlrBOalJ9O7Oz3Al3
47bIKAyAPsqt18QXthdpdSsBmQ4awj5Lo4rlS4P2tFHkZ3tnTQKTcTlHGGdm26d2
DUw6CV9hmcT/ipoVRey/yTUdYO/1u0lrqpRJ4B5qJu6HBJ3lnqp2Uj6f7FINEd5R
YMbKvhmierGBkSg84fmBHZluK8iSMZwdU7p/u9DZ2Wvp2CG5kyb2q2aWL/pwXrL1
XjKLQsFf9U7rOdtcT0ZusL8sfey6+u+v91wIyXUZ2xXsUru4RKbgRhXFfJQbGy7p
sxHKGNmRlggpj5RrWJvoREqPkkj79RzwQbkzr6CaiDIjaLriaAfXVyCkc7+N5JdG
HlVNUH3atAu5/Byi3tbai0ugZPiE/mzFe+1iM04vpvtY6e7tXGx12dKDna9nSeGI
G7wHhHZ1MyZRgNr54oemzxdXGb9Ez2bLdbR+1XPiQ/VK6ITSSMxWjCWPjwaFBUJT
SmPhiw9lCzetSFUfiDT0npX64ekOBBuNuqO3cZzvjc/ZJtW2VbNX1/EgNGfeSKZt
NhsmDpSgcYN1/tzAG5ln2ID12U9j2/pKx67Xs7IBrypWhotsGiKOQ0K3/6MAxuVS
35tdNnm64rNfW4+VEWbUnxRmLhGtYdfYgSzN0lRj3TT59S++hYM=
=Hr3H
-----END PGP SIGNATURE-----