#1142717 glib2.0: CVE-2026-16118

Package:
src:glib2.0
Source:
src:glib2.0
Submitter:
Salvatore Bonaccorso
Date:
2026-08-31 14:49:05 UTC
Severity:
normal
Tags:
#1142717#5
Date:
2026-07-24 13:37:42 UTC
From:
To:
Hi,

The following vulnerability was published for glib2.0.

CVE-2026-16118[0]:
| A flaw was found in xdgmime. A heap-based buffer overflow can be
| triggered in _xdg_mime_magic_parse_magic_line() in the
| xdgmimemagic.c file on little-endian systems when an attacker-
| controlled MIME magic file in a user-writable XDG data location
| (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an
| application performing MIME type detection (e.g., via
| g_content_type_guess()). When performing byte-swap, incorrect
| pointer arithmetic on the write side causes an out-of-bounds write
| of 2 bytes, resulting in an application crash or memory corruption.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-16118
https://www.cve.org/CVERecord?id=CVE-2026-16118
[1] https://gitlab.gnome.org/GNOME/glib/-/work_items/3992

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1142717#10
Date:
2026-07-24 14:08:18 UTC
From:
To:
I'm having a hard time thinking of reasons why this would be crossing a
security boundary: if a program has the ability to write to
$XDG_DATA_HOME then it's already part of the trusted computing base for
this user (for example it could configure `systemd --user` to run
arbitrary code), and I can't think of a reason why it would be desirable
to let untrusted/sandboxed software write to $XDG_DATA_HOME/mime/magic,
which would let that software change the rules by which files are
classified into their MIME types.

(Flatpak apps can export a file into XDG_DATA_HOME/mime/packages, but
not into .../magic.)

     smcv

#1142717#15
Date:
2026-07-24 20:00:53 UTC
From:
To:
Hi Simon,

I highly appreciate that you took time to do an assessment here, given
the amount of incoming CVEs the primarily focus here was to first
report the new one to the maintainers and do an assessment on the
severity later.

I will mark the CVE as no-dsa and guess you will agree on it.

Regards,
Salvatore

#1142717#20
Date:
2026-08-12 09:11:13 UTC
From:
To:
Hello,

Bug #1142717 in glib reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/gnome-team/glib/-/commit/18458fa8f080727801e87432e23acef9afb61dda
------------------------------------------------------------------------
d/patches: Add patch from upstream to address CVE-2026-16118

Closes: #1142717
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142717

#1142717#25
Date:
2026-08-12 09:13:01 UTC
From:
To:
Hello,

Bug #1142717 in glib reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/gnome-team/glib/-/commit/6e40639efd2ba873667f13f327068533410c3a90
------------------------------------------------------------------------
d/patches: Add patch from upstream to address CVE-2026-16118

Closes: #1142717
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142717

#1142717#28
Date:
2026-08-12 09:13:01 UTC
From:
To:
Hello,

Bug #1142717 in glib reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/gnome-team/glib/-/commit/18458fa8f080727801e87432e23acef9afb61dda
------------------------------------------------------------------------
d/patches: Add patch from upstream to address CVE-2026-16118

Closes: #1142717
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142717

#1142717#33
Date:
2026-08-12 09:36:01 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
glib2.0, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142717@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon McVittie <smcv@debian.org> (supplier of updated glib2.0 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 12 Aug 2026 10:10:25 +0100
Source: glib2.0
Architecture: source
Version: 2.88.3-3
Distribution: unstable
Urgency: medium
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Closes: 1142717
Changes:
 glib2.0 (2.88.3-3) unstable; urgency=medium
 .
   * d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,
     d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:
     Add patches from upstream (to be released in 2.89.4) to address
     an out-of-bounds write if parsing a crafted XDG MIME magic file,
     and fix a related test failure on minimal systems
     (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)
Checksums-Sha1:
 060a88b44df733ee92680f9c106d1f9a599f8b8d 5091 glib2.0_2.88.3-3.dsc
 4dfd103c4aca09d825a83b736e8d57fc7cc5a080 146728 glib2.0_2.88.3-3.debian.tar.xz
 cc1b678ad5c92135315fc3153bdb190bda22e887 15783988 glib2.0_2.88.3-3.git.tar.xz
 661a1e16f75301d5ceec1602a4b1255016e5b862 17556 glib2.0_2.88.3-3_source.buildinfo
Checksums-Sha256:
 36848fbcc2718313c03b34150cec8ab921ffa3790d14d16bf5906b364c5a3798 5091 glib2.0_2.88.3-3.dsc
 8109e35ac5fd6cfc72c913357b667a584bcdb8f20efa119337db407139f34bb7 146728 glib2.0_2.88.3-3.debian.tar.xz
 ada1e7b3c50596f80355a191c30f866762cb5d9417f487e4576b6bb17387f05c 15783988 glib2.0_2.88.3-3.git.tar.xz
 e471ebe2691e20e582f7b25c0a06fe4e396f132e5086636d78811976e909029d 17556 glib2.0_2.88.3-3_source.buildinfo
Files:
 09ef239c61ccff5d7b78e83c12328984 5091 libs optional glib2.0_2.88.3-3.dsc
 16db7c7cb1714a7e9be8c3d37b826630 146728 libs optional glib2.0_2.88.3-3.debian.tar.xz
 1592d1cb6e8da540059699d8e5192eda 15783988 libs None glib2.0_2.88.3-3.git.tar.xz
 8e9215742f85d5a2e0655d04ccc52813 17556 libs optional glib2.0_2.88.3-3_source.buildinfo
Git-Tag-Info: tag=46316932734b6f0fc0346a69bc8908a9ca4e7d30 fp=7a073ad1ae694fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie <smcv@debian.org>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmp8ORoACgkQYG0ITkaD
wHkr0g/+L0nOAYoTXNJgDrgSHMC5cN4jCSIyn8hFB3TxwwWy2AFzzwZpvBwSkqbD
vk3bMBfz/DJszyp0GCO+dtX1RVTNIc5FO4kpLsBdVVBo41kWG56ID2fJSJGra+tt
2USkORUTFUmGCzJWiV2/9JowGWySgdaMXBjSBYwTvl+QN9xkzV+eXzTO17MMCaH4
XOVEfhCMHMiezFY23vIjl/9J+IT98INLJh4YtYNJsvub5tqoYa55UcCgkLYejkFP
MgASBeA8yDs9YaztxLtibXqhTvmEIaFil1D1L4W2j786wL0VUHN6Kieb4hKohLV2
HvBga+zEfRJoXypIpdxTkNZRGRqSRaE9zwekjxfbLU4QQBFNV3qOUECpSgwJCv4w
JgWsUXhD1EEGbSJGYDQi/Wdnx1hcvnmESScjnBCDxPjz6WzW3rzzOAAa7yidCVNS
WX5t5MfPgNxdX3PCvBO14nePJ7jjCYD4YXvwif8x1oO6otbzaHAp29fXQ5fW2EZn
QrbMZni76rrGjtX+IUAR9zswYvKz8ygqF1CMMVcDqjoNJoQkgKFHAT+clzXjymPy
vJvPged4H+b6pzoTIM7mNWX08fMpMyRUEcRWLGPXW81M4LVnFF3xkQUPhPJlazl4
XcbcTCD7GWzUdhDx2FC2wsfkReBGAHTelPSXKN5NmhrlRuNuZDU=
=jGDe
-----END PGP SIGNATURE-----

#1142717#38
Date:
2026-08-12 20:49:04 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
glib2.0, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142717@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon McVittie <smcv@debian.org> (supplier of updated glib2.0 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 12 Aug 2026 21:28:14 +0100
Source: glib2.0
Architecture: source
Version: 2.89.3-4
Distribution: experimental
Urgency: medium
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Closes: 1142717
Changes:
 glib2.0 (2.89.3-4) experimental; urgency=medium
 .
   * Merge from unstable
     - d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,
       d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:
       Add patches from upstream (to be released in 2.89.4) to address
       an out-of-bounds write if parsing a crafted XDG MIME magic file,
       and fix a related test failure on minimal systems
       (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)
   * d/p/workarounds: Mark memory-monitor-psi tests as flaky
     (Mitigates: #1143197, #1143241)
Checksums-Sha1:
 be33c1732a99c9dbfde2add3f590c0be5f7299d2 5075 glib2.0_2.89.3-4.dsc
 fe3033fd79d181078a9fc12726d29d0b351e65b9 145252 glib2.0_2.89.3-4.debian.tar.xz
 40ac9aa632a0202d5fe31a9ad3f15e901904ef50 17867576 glib2.0_2.89.3-4.git.tar.xz
 03cf9e2f8f3d5a48a8a186becb6e57b3bb6ff40e 17556 glib2.0_2.89.3-4_source.buildinfo
Checksums-Sha256:
 e547e77a3ded67585370610efb49326684c36f84c2baf1715c8d36282610a7ed 5075 glib2.0_2.89.3-4.dsc
 01256d2c7d7d1e3f11beef4344d3d42e996c759e9a3ce38ad029f21aad61974b 145252 glib2.0_2.89.3-4.debian.tar.xz
 fd6b3647be124835deec286b643a7c593ba2a697139e6c95241e287bc2ba9818 17867576 glib2.0_2.89.3-4.git.tar.xz
 ac998f5eb04f41f2a4c69ac2c797938c43ec4af25b59c0a62d7d6b74003e1c8a 17556 glib2.0_2.89.3-4_source.buildinfo
Files:
 70d0f5f91ca1488c214d6df2cbe5abf3 5075 libs optional glib2.0_2.89.3-4.dsc
 a8c672480b890d175ecd9b0da4404584 145252 libs optional glib2.0_2.89.3-4.debian.tar.xz
 723016c4074a6aa6651a49acfe5292cc 17867576 libs None glib2.0_2.89.3-4.git.tar.xz
 c7e56fda286378178c61655d02606679 17556 libs optional glib2.0_2.89.3-4_source.buildinfo
Git-Tag-Info: tag=aded4d4c0b76d84d188d71c9622bb781642aed63 fp=7a073ad1ae694fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie <smcv@debian.org>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmp82BsACgkQYG0ITkaD
wHmB9g/8DEC+PtGNpNOpKt5jpJqjJnPKUyKVavZnZ2fl2KwGxtSC9GZR2dMIRlwJ
cl4zXzXtqrx1fOkuK0sZg2EMKK1+D+ytfIAaP4LOb3NW7rJ7zq6b6K6WQ3Y/JJVM
ySupgAbQjgd8Fk449Zeon6lvfzymCbdMHTHpDS75ZluE7Jkbn7/yfUtsavcXbdnL
rMPKmM6Z2fL6G2Z4T0aSxCiDGKO9KL1ndPYad6MqGoL9bIni9OBXcqdkOhhtk6ji
MixEoYZ1pY6krfggzPpImbjCH7oASTCmrYegfQW4RLYxwFYvrdlThQyqRH77XXZt
BzcTReJpSHbXtXURt/OayusEZznIpMDJsZQQyX+kwJhGn0g4GrN2jIs/Sp6emK7y
WGla00PBgikdHOoGWfGvUwJkhs43zfkGJGPGM4qOJdBZl+oT5WMsD7s/HF2LWnMb
VoMiDnNLEB0hwmMPbKrXM0090F7K4VCDldplqrULUdQ0QHYpfupFe+ORfXANwFtc
KgJ15gnOcMf6OmR2G6Pyz73WDz0t61defqyHAMIxx1m4OLYz+L1VRSvlFvlQola0
2qNGUhiHwRR1F2oRc8JOltJTzahBoKHeKDYj6MLMbmEH6q+ERANPdBe4/1dggiEV
60wLGuh9sVSPYjU0pVscZNKYbrC7Y7O4HQ82aLxmRzQLmemoxe0=
=7oCK
-----END PGP SIGNATURE-----

#1142717#43
Date:
2026-08-21 15:14:28 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
glib2.0, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142717@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jeremy Bícha <jbicha@ubuntu.com> (supplier of updated glib2.0 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 21 Aug 2026 16:37:11 +0200
Source: glib2.0
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 2.89.3-5
Distribution: unstable
Urgency: medium
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Jeremy Bícha <jbicha@ubuntu.com>
Closes: 1141316 1142717 1142835
Changes:
 glib2.0 (2.89.3-5) unstable; urgency=medium
 .
   * Release to unstable
 .
 glib2.0 (2.89.3-4) experimental; urgency=medium
 .
   * Merge from unstable
     - d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,
       d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:
       Add patches from upstream (to be released in 2.89.4) to address
       an out-of-bounds write if parsing a crafted XDG MIME magic file,
       and fix a related test failure on minimal systems
       (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)
   * d/p/workarounds: Mark memory-monitor-psi tests as flaky
     (Mitigates: #1143197, #1143241)
 .
 glib2.0 (2.89.3-3) experimental; urgency=medium
 .
   [ Simon McVittie ]
   * Merge packaging from unstable
     - d/tests/1065022-futureproofing: Make the test pass more reliably,
       by ensuring that user-session-migration gets removed rather than
       making libglib2.0-0t64 be reinstalled
   * Drop patches added by 2.88.3-2, already part of 2.89.x
 .
 glib2.0 (2.89.3-2) experimental; urgency=medium
 .
   * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:
     Add patch from upstream to fix autopkgtest regression
   * d/changelog: Mention CVE-2026-15588, CVE-2026-58016 in the appropriate
     previous changelog entry
 .
 glib2.0 (2.89.3-1) experimental; urgency=medium
 .
   * New upstream release
   * debian/libglib2.0-0t64.symbols: Add new symbols
 .
 glib2.0 (2.89.2-1) experimental; urgency=medium
 .
   * New upstream release
     - Fixes possible integer underflow when parsing D-Bus introspection XML
       (CVE-2026-58016, Closes: #1141316)
     - Fixes resource exhaustion if a malicious client can contact a GDBusServer
       (CVE-2026-15588, Closes: #1142835)
   * d/p: Refresh patches
   * d/libglib2.0-0t64.symbols: Add new symbol
Checksums-Sha1:
 92f5c3d181b04bdf2bd126fd09f1c7d47d33d99b 4809 glib2.0_2.89.3-5.dsc
 af3872a6ab841fbd4618d11dcda02317a2fea995 145180 glib2.0_2.89.3-5.debian.tar.xz
 c14291048b10042d3ac029149f7e2baff3e6fac3 11637 glib2.0_2.89.3-5_source.buildinfo
Checksums-Sha256:
 d051d1b8f572ce65c8959d97d6433c2c685c6374fbf52a71d11fbadfe210e701 4809 glib2.0_2.89.3-5.dsc
 0fe2c3c9bf1a90376edb6ec3e4e602190b9df72c987cf3f3961e0a132d4aa5fb 145180 glib2.0_2.89.3-5.debian.tar.xz
 f57785267e300de810197e17b7dea6a05c60ee2aa8aa39ef041c0ea105c8208b 11637 glib2.0_2.89.3-5_source.buildinfo
Files:
 51909061d0431c875d197b9aa150a732 4809 libs optional glib2.0_2.89.3-5.dsc
 f7eb67b8b062f653390d1b9ca48502f8 145180 libs optional glib2.0_2.89.3-5.debian.tar.xz
 1677d300f3671162f2584bca30d78f2f 11637 libs optional glib2.0_2.89.3-5_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmqIYuYACgkQ5mx3Wuv+
bH1LlBAA0sAu2oTrdbp5reAEPTYrtgzuEM3RZvfZZ9PFjyXnlrBOalJ9O7Oz3Al3
47bIKAyAPsqt18QXthdpdSsBmQ4awj5Lo4rlS4P2tFHkZ3tnTQKTcTlHGGdm26d2
DUw6CV9hmcT/ipoVRey/yTUdYO/1u0lrqpRJ4B5qJu6HBJ3lnqp2Uj6f7FINEd5R
YMbKvhmierGBkSg84fmBHZluK8iSMZwdU7p/u9DZ2Wvp2CG5kyb2q2aWL/pwXrL1
XjKLQsFf9U7rOdtcT0ZusL8sfey6+u+v91wIyXUZ2xXsUru4RKbgRhXFfJQbGy7p
sxHKGNmRlggpj5RrWJvoREqPkkj79RzwQbkzr6CaiDIjaLriaAfXVyCkc7+N5JdG
HlVNUH3atAu5/Byi3tbai0ugZPiE/mzFe+1iM04vpvtY6e7tXGx12dKDna9nSeGI
G7wHhHZ1MyZRgNr54oemzxdXGb9Ez2bLdbR+1XPiQ/VK6ITSSMxWjCWPjwaFBUJT
SmPhiw9lCzetSFUfiDT0npX64ekOBBuNuqO3cZzvjc/ZJtW2VbNX1/EgNGfeSKZt
NhsmDpSgcYN1/tzAG5ln2ID12U9j2/pKx67Xs7IBrypWhotsGiKOQ0K3/6MAxuVS
35tdNnm64rNfW4+VEWbUnxRmLhGtYdfYgSzN0lRj3TT59S++hYM=
=Hr3H
-----END PGP SIGNATURE-----

#1142717#48
Date:
2026-08-31 14:47:20 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
glib2.0, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142717@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon McVittie <smcv@debian.org> (supplier of updated glib2.0 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 23 Aug 2026 15:20:28 +0100
Source: glib2.0
Architecture: source
Version: 2.84.4-3~deb13u5
Distribution: trixie
Urgency: medium
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Closes: 1141316 1142717 1142835
Changes:
 glib2.0 (2.84.4-3~deb13u5) trixie; urgency=medium
 .
   * Add patches from upstream 2.89.x to fix parsing of XDG MIME magic
     datafiles
     - d/p/CVE-2026-16118/xdgmime-Check-if-caches-are-set-before-dumping-them.patch:
       Fix a crash when running tests on a minimal system
     - d/p/CVE-2026-16118/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:
       Fix an out-of-bounds write if parsing attacker-controlled MIME-magic
       data. This is unlikely to be exploitable in practice, because an
       attacker with write access to $XDG_DATA_HOME/mime/magic is likely
       to have other ways to cause arbitrary code execution.
       (CVE-2026-16118, glib#3992 upstream, Closes: #1142717)
 .
 glib2.0 (2.84.4-3~deb13u4) trixie; urgency=medium
 .
   * Edit previous changelog entry to correlate CVE fixes with upstream
     bug numbers and releases
   * Add patches from upstream 2.86.5 to fix out-of-bounds accesses:
     - d/p/gvariant-Fix-an-off-by-one-error-in-an-offset-comparison.patch:
       Fix a potential out of bounds read by 1 byte
       (CVE-2026-58010, glib#3915 upstream)
     - d/p/gmarkup-Fix-potential-one-byte-overread-in-g_markup_escap.patch:
       Fix a potential out of bounds read by 1 byte when escaping text that
       is not valid UTF-8
       (not considered to be a vulnerability, glib#3916 upstream)
     - d/p/gdatetime-Factor-out-a-couple-of-magic-constants.patch,
       d/p/gdatetime-Add-missing-range-validation-to-g_date_time_add.patch:
       Fix an out of bounds read by up to 2 bytes after parsing an
       out-of-range date
       (CVE-2026-58011, glib#3917 upstream)
     - d/p/gregex-Fix-case-changing-substitutions-with-G_REGEX_RAW.patch:
       Fix a potential buffer overflow when changing the case of an incomplete
       UTF-8 sequence while using G_REGEX_RAW
       (CVE-2026-58012, glib#3918 upstream)
     - d/p/gregex-Fix-use-of-wrong-option-flags-set-for-checking-for.patch,
       d/p/gregex-Rename-the-compile_opts-members-to-clarify-their-t.patch:
       Fix an out-of-bounds read when g_regex_split_full() acts on
       invalid UTF-8
       (not considered to be a vulnerability, glib#3919 upstream)
   * Add patches from upstream 2.88.1 to fix several issues that were reported
     as potential security vulnerabilities:
     - d/p/giochannel-Fix-memcmp-off-the-end-of-the-buffer-with-long.patch:
       Fix out-of-bounds read if a GIOChannel is configured with a long
       line-terminator
       (CVE-2026-58013, glib#3825 upstream)
     - d/p/gkeyfile-Fix-a-one-byte-heap-under-read-with-g_key_file_g.patch:
       Fix out-of-bounds read if a list of locale-dependent strings in a
       GKeyFile is empty
       (CVE-2026-58014, glib#3930 upstream)
     - d/p/gdbusmessage-Fix-types-of-integer-arithmetic-in-message-l.patch:
       Fix an integer overflow that could lead to accepting overly large
       messages on peer-to-peer D-Bus connections
       (no CVE ID, glib#3933 upstream)
     - d/p/gdbusauthmechanismsha1-Validate-cookie-context.patch,
       d/p/gdbusauthmechanismsha1-Improve-validation-of-cookie-ID.patch,
       d/p/gdbusauthmechanism-Expose-client-reject-reason-as-a-new-v.patch,
       d/p/tests-Add-a-unit-test-for-GDBusAuthMechanismSha1-cookie-c.patch:
       Prevent path traversal and file-content disclosure if a D-Bus client
       connects to a malicious peer-to-peer D-Bus server
       (CVE-2026-58015, glib#3931 upstream)
   * Add patch from upstream 2.88.3 fixing a possible denial of service:
     - d/p/gdbusauth-Limit-length-of-lines-read-from-client.patch:
       Fix resource exhaustion if a malicious client can contact a
       GDBusServer
       (CVE-2026-15588, glib#3985 upstream, Closes: #1142835)
   * Add patches from upstream 2.89.0 to harden D-Bus introspection parsing
     - d/p/gdbusintrospection-Add-some-assertions-before-array-deref.patch,
       d/p/tests-Improve-D-Bus-introspection-test-paths.patch,
       d/p/gdbusintrospection-Fix-XML-parser-state-handling-for-node.patch,
       d/p/fuzzing-Add-a-fuzz-test-for-g_dbus_node_info_new_for_xml.patch:
       Avoid a possible integer underflow if parsing malformed D-Bus
       introspection XML sent by a malicious service
       (glib#3932 upstream, CVE-2026-58016, Closes: #1141316)
   * d/salsa-ci.yml: Disable uscan job as not relevant to this stable branch
Checksums-Sha1:
 02513a8ebbd960c5029e900fafccfe8ea93c8c4f 5294 glib2.0_2.84.4-3~deb13u5.dsc
 6d92bf8dffbeee2369394a9f40a67f8fb71b478c 172260 glib2.0_2.84.4-3~deb13u5.debian.tar.xz
 9b353f9d539cfed5d37a00add9f33829a35063fb 15145332 glib2.0_2.84.4-3~deb13u5.git.tar.xz
 8855a2e8cea6ab6fb2aa6d69cb891ed56dd04790 17696 glib2.0_2.84.4-3~deb13u5_source.buildinfo
Checksums-Sha256:
 2587beb2f5b90511d0c88a7595c1d3b3ea7a5b7e6582713ecae3713864012858 5294 glib2.0_2.84.4-3~deb13u5.dsc
 d8e3603c3780d2cc883d762cf81db9199d8c4c492a82a1a791c117a6d402dbeb 172260 glib2.0_2.84.4-3~deb13u5.debian.tar.xz
 568239a3a604022dec493408d0fc10f165639dd19a1eb20f8b01634ee0ce19bc 15145332 glib2.0_2.84.4-3~deb13u5.git.tar.xz
 8daca739c81b87175322561351976ae779c7e2764982c9cb32949ccf9c881339 17696 glib2.0_2.84.4-3~deb13u5_source.buildinfo
Files:
 d257f9927ee86ee1be6df1acea8c9efa 5294 libs optional glib2.0_2.84.4-3~deb13u5.dsc
 3465d9f4fbaee31d4d9bf933b3ad43ed 172260 libs optional glib2.0_2.84.4-3~deb13u5.debian.tar.xz
 9b23023f29becc2b6b956a29d32bd55c 15145332 libs optional glib2.0_2.84.4-3~deb13u5.git.tar.xz
 83e336a108cd04d0d64352d6efb7fde4 17696 libs optional glib2.0_2.84.4-3~deb13u5_source.buildinfo
Git-Tag-Info: tag=eb1c6804e6bb2fa38dec94d4037e3b30a55fbf5d fp=7a073ad1ae694fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie <smcv@debian.org>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqLMEoACgkQYG0ITkaD
wHnzZg//bOMScFzHsYV/2U6cdqWd3BgRMvfn/rJMCEwxQXTrUsAmn/DHSsHqlgxs
mY5Qk+PfHwcPfF3rKiRCM5VZs4WoWwd611EAyr57viNhT4RRMOqEbw393f63CSMn
MlmRu208MvW6S/gsJfol+tIZUFwaSkZX6Q0cS90SkQIPDuWQZFq+VsfRdy+y785x
gkkGyeB1U/rQaeVLVu6jTOvPQ36yY9bg8xPfwm0Zf5Jrjy2rK9PZB7SoFcx3kPkL
bKHIf9gsrtiGBb6p8knovwEUXF/6ngNRlBvyN4AaGAe9gXArHfTe9wiYSup0dd0h
/p5mrzE/2WgDrdIEqbBMSUm5iRqIcpvhkSmCDZ3/GUPHPxubiGJBFDz8nDAvjwMm
L05T9QNq4Q6aLtKqsf29+QTvIpMtqSgsX7Kua+llyTOrpKCkWiXijXDOC0hX8m4M
Q7F1uXh59fHMQLn5TexLxR/DyKg80TO9bpUa1Be1vNNhQ854I6arINKngHT08M0a
MAbtlO/DAjndPSspIVrxKPcv6kqAP4SZRZgcrwoY6Q2t6n7RKyi5kONjhYal0Ik8
JJH/onvUo2gV65Oq2U7qVQGiHlUHDi2qStKakY67BnXW3qD5I46TYZrytr1y3iNa
CibI1nztFPKagzevQALSAPr2JybeKIMf1o1NT9TIBcHI9J37IoE=
=B3I3
-----END PGP SIGNATURE-----