#1142717 glib2.0: CVE-2026-16118

Package:
src:glib2.0
Source:
src:glib2.0
Submitter:
Salvatore Bonaccorso
Date:
2026-08-21 15:17:02 UTC
Severity:
normal
Tags:
#1142717#5
Date:
2026-07-24 13:37:42 UTC
From:
To:
Hi,

The following vulnerability was published for glib2.0.

CVE-2026-16118[0]:
| A flaw was found in xdgmime. A heap-based buffer overflow can be
| triggered in _xdg_mime_magic_parse_magic_line() in the
| xdgmimemagic.c file on little-endian systems when an attacker-
| controlled MIME magic file in a user-writable XDG data location
| (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an
| application performing MIME type detection (e.g., via
| g_content_type_guess()). When performing byte-swap, incorrect
| pointer arithmetic on the write side causes an out-of-bounds write
| of 2 bytes, resulting in an application crash or memory corruption.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-16118
https://www.cve.org/CVERecord?id=CVE-2026-16118
[1] https://gitlab.gnome.org/GNOME/glib/-/work_items/3992

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1142717#10
Date:
2026-07-24 14:08:18 UTC
From:
To:
I'm having a hard time thinking of reasons why this would be crossing a
security boundary: if a program has the ability to write to
$XDG_DATA_HOME then it's already part of the trusted computing base for
this user (for example it could configure `systemd --user` to run
arbitrary code), and I can't think of a reason why it would be desirable
to let untrusted/sandboxed software write to $XDG_DATA_HOME/mime/magic,
which would let that software change the rules by which files are
classified into their MIME types.

(Flatpak apps can export a file into XDG_DATA_HOME/mime/packages, but
not into .../magic.)

     smcv

#1142717#15
Date:
2026-07-24 20:00:53 UTC
From:
To:
Hi Simon,

I highly appreciate that you took time to do an assessment here, given
the amount of incoming CVEs the primarily focus here was to first
report the new one to the maintainers and do an assessment on the
severity later.

I will mark the CVE as no-dsa and guess you will agree on it.

Regards,
Salvatore

#1142717#20
Date:
2026-08-12 09:11:13 UTC
From:
To:
Hello,

Bug #1142717 in glib reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/gnome-team/glib/-/commit/18458fa8f080727801e87432e23acef9afb61dda
------------------------------------------------------------------------
d/patches: Add patch from upstream to address CVE-2026-16118

Closes: #1142717
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142717

#1142717#25
Date:
2026-08-12 09:13:01 UTC
From:
To:
Hello,

Bug #1142717 in glib reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/gnome-team/glib/-/commit/6e40639efd2ba873667f13f327068533410c3a90
------------------------------------------------------------------------
d/patches: Add patch from upstream to address CVE-2026-16118

Closes: #1142717
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142717

#1142717#28
Date:
2026-08-12 09:13:01 UTC
From:
To:
Hello,

Bug #1142717 in glib reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/gnome-team/glib/-/commit/18458fa8f080727801e87432e23acef9afb61dda
------------------------------------------------------------------------
d/patches: Add patch from upstream to address CVE-2026-16118

Closes: #1142717
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1142717

#1142717#33
Date:
2026-08-12 09:36:01 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
glib2.0, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142717@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon McVittie <smcv@debian.org> (supplier of updated glib2.0 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 12 Aug 2026 10:10:25 +0100
Source: glib2.0
Architecture: source
Version: 2.88.3-3
Distribution: unstable
Urgency: medium
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Closes: 1142717
Changes:
 glib2.0 (2.88.3-3) unstable; urgency=medium
 .
   * d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,
     d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:
     Add patches from upstream (to be released in 2.89.4) to address
     an out-of-bounds write if parsing a crafted XDG MIME magic file,
     and fix a related test failure on minimal systems
     (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)
Checksums-Sha1:
 060a88b44df733ee92680f9c106d1f9a599f8b8d 5091 glib2.0_2.88.3-3.dsc
 4dfd103c4aca09d825a83b736e8d57fc7cc5a080 146728 glib2.0_2.88.3-3.debian.tar.xz
 cc1b678ad5c92135315fc3153bdb190bda22e887 15783988 glib2.0_2.88.3-3.git.tar.xz
 661a1e16f75301d5ceec1602a4b1255016e5b862 17556 glib2.0_2.88.3-3_source.buildinfo
Checksums-Sha256:
 36848fbcc2718313c03b34150cec8ab921ffa3790d14d16bf5906b364c5a3798 5091 glib2.0_2.88.3-3.dsc
 8109e35ac5fd6cfc72c913357b667a584bcdb8f20efa119337db407139f34bb7 146728 glib2.0_2.88.3-3.debian.tar.xz
 ada1e7b3c50596f80355a191c30f866762cb5d9417f487e4576b6bb17387f05c 15783988 glib2.0_2.88.3-3.git.tar.xz
 e471ebe2691e20e582f7b25c0a06fe4e396f132e5086636d78811976e909029d 17556 glib2.0_2.88.3-3_source.buildinfo
Files:
 09ef239c61ccff5d7b78e83c12328984 5091 libs optional glib2.0_2.88.3-3.dsc
 16db7c7cb1714a7e9be8c3d37b826630 146728 libs optional glib2.0_2.88.3-3.debian.tar.xz
 1592d1cb6e8da540059699d8e5192eda 15783988 libs None glib2.0_2.88.3-3.git.tar.xz
 8e9215742f85d5a2e0655d04ccc52813 17556 libs optional glib2.0_2.88.3-3_source.buildinfo
Git-Tag-Info: tag=46316932734b6f0fc0346a69bc8908a9ca4e7d30 fp=7a073ad1ae694fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie <smcv@debian.org>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmp8ORoACgkQYG0ITkaD
wHkr0g/+L0nOAYoTXNJgDrgSHMC5cN4jCSIyn8hFB3TxwwWy2AFzzwZpvBwSkqbD
vk3bMBfz/DJszyp0GCO+dtX1RVTNIc5FO4kpLsBdVVBo41kWG56ID2fJSJGra+tt
2USkORUTFUmGCzJWiV2/9JowGWySgdaMXBjSBYwTvl+QN9xkzV+eXzTO17MMCaH4
XOVEfhCMHMiezFY23vIjl/9J+IT98INLJh4YtYNJsvub5tqoYa55UcCgkLYejkFP
MgASBeA8yDs9YaztxLtibXqhTvmEIaFil1D1L4W2j786wL0VUHN6Kieb4hKohLV2
HvBga+zEfRJoXypIpdxTkNZRGRqSRaE9zwekjxfbLU4QQBFNV3qOUECpSgwJCv4w
JgWsUXhD1EEGbSJGYDQi/Wdnx1hcvnmESScjnBCDxPjz6WzW3rzzOAAa7yidCVNS
WX5t5MfPgNxdX3PCvBO14nePJ7jjCYD4YXvwif8x1oO6otbzaHAp29fXQ5fW2EZn
QrbMZni76rrGjtX+IUAR9zswYvKz8ygqF1CMMVcDqjoNJoQkgKFHAT+clzXjymPy
vJvPged4H+b6pzoTIM7mNWX08fMpMyRUEcRWLGPXW81M4LVnFF3xkQUPhPJlazl4
XcbcTCD7GWzUdhDx2FC2wsfkReBGAHTelPSXKN5NmhrlRuNuZDU=
=jGDe
-----END PGP SIGNATURE-----

#1142717#38
Date:
2026-08-12 20:49:04 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
glib2.0, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142717@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon McVittie <smcv@debian.org> (supplier of updated glib2.0 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 12 Aug 2026 21:28:14 +0100
Source: glib2.0
Architecture: source
Version: 2.89.3-4
Distribution: experimental
Urgency: medium
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Closes: 1142717
Changes:
 glib2.0 (2.89.3-4) experimental; urgency=medium
 .
   * Merge from unstable
     - d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,
       d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:
       Add patches from upstream (to be released in 2.89.4) to address
       an out-of-bounds write if parsing a crafted XDG MIME magic file,
       and fix a related test failure on minimal systems
       (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)
   * d/p/workarounds: Mark memory-monitor-psi tests as flaky
     (Mitigates: #1143197, #1143241)
Checksums-Sha1:
 be33c1732a99c9dbfde2add3f590c0be5f7299d2 5075 glib2.0_2.89.3-4.dsc
 fe3033fd79d181078a9fc12726d29d0b351e65b9 145252 glib2.0_2.89.3-4.debian.tar.xz
 40ac9aa632a0202d5fe31a9ad3f15e901904ef50 17867576 glib2.0_2.89.3-4.git.tar.xz
 03cf9e2f8f3d5a48a8a186becb6e57b3bb6ff40e 17556 glib2.0_2.89.3-4_source.buildinfo
Checksums-Sha256:
 e547e77a3ded67585370610efb49326684c36f84c2baf1715c8d36282610a7ed 5075 glib2.0_2.89.3-4.dsc
 01256d2c7d7d1e3f11beef4344d3d42e996c759e9a3ce38ad029f21aad61974b 145252 glib2.0_2.89.3-4.debian.tar.xz
 fd6b3647be124835deec286b643a7c593ba2a697139e6c95241e287bc2ba9818 17867576 glib2.0_2.89.3-4.git.tar.xz
 ac998f5eb04f41f2a4c69ac2c797938c43ec4af25b59c0a62d7d6b74003e1c8a 17556 glib2.0_2.89.3-4_source.buildinfo
Files:
 70d0f5f91ca1488c214d6df2cbe5abf3 5075 libs optional glib2.0_2.89.3-4.dsc
 a8c672480b890d175ecd9b0da4404584 145252 libs optional glib2.0_2.89.3-4.debian.tar.xz
 723016c4074a6aa6651a49acfe5292cc 17867576 libs None glib2.0_2.89.3-4.git.tar.xz
 c7e56fda286378178c61655d02606679 17556 libs optional glib2.0_2.89.3-4_source.buildinfo
Git-Tag-Info: tag=aded4d4c0b76d84d188d71c9622bb781642aed63 fp=7a073ad1ae694fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie <smcv@debian.org>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmp82BsACgkQYG0ITkaD
wHmB9g/8DEC+PtGNpNOpKt5jpJqjJnPKUyKVavZnZ2fl2KwGxtSC9GZR2dMIRlwJ
cl4zXzXtqrx1fOkuK0sZg2EMKK1+D+ytfIAaP4LOb3NW7rJ7zq6b6K6WQ3Y/JJVM
ySupgAbQjgd8Fk449Zeon6lvfzymCbdMHTHpDS75ZluE7Jkbn7/yfUtsavcXbdnL
rMPKmM6Z2fL6G2Z4T0aSxCiDGKO9KL1ndPYad6MqGoL9bIni9OBXcqdkOhhtk6ji
MixEoYZ1pY6krfggzPpImbjCH7oASTCmrYegfQW4RLYxwFYvrdlThQyqRH77XXZt
BzcTReJpSHbXtXURt/OayusEZznIpMDJsZQQyX+kwJhGn0g4GrN2jIs/Sp6emK7y
WGla00PBgikdHOoGWfGvUwJkhs43zfkGJGPGM4qOJdBZl+oT5WMsD7s/HF2LWnMb
VoMiDnNLEB0hwmMPbKrXM0090F7K4VCDldplqrULUdQ0QHYpfupFe+ORfXANwFtc
KgJ15gnOcMf6OmR2G6Pyz73WDz0t61defqyHAMIxx1m4OLYz+L1VRSvlFvlQola0
2qNGUhiHwRR1F2oRc8JOltJTzahBoKHeKDYj6MLMbmEH6q+ERANPdBe4/1dggiEV
60wLGuh9sVSPYjU0pVscZNKYbrC7Y7O4HQ82aLxmRzQLmemoxe0=
=7oCK
-----END PGP SIGNATURE-----

#1142717#43
Date:
2026-08-21 15:14:28 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
glib2.0, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142717@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jeremy Bícha <jbicha@ubuntu.com> (supplier of updated glib2.0 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 21 Aug 2026 16:37:11 +0200
Source: glib2.0
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 2.89.3-5
Distribution: unstable
Urgency: medium
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Jeremy Bícha <jbicha@ubuntu.com>
Closes: 1141316 1142717 1142835
Changes:
 glib2.0 (2.89.3-5) unstable; urgency=medium
 .
   * Release to unstable
 .
 glib2.0 (2.89.3-4) experimental; urgency=medium
 .
   * Merge from unstable
     - d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,
       d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:
       Add patches from upstream (to be released in 2.89.4) to address
       an out-of-bounds write if parsing a crafted XDG MIME magic file,
       and fix a related test failure on minimal systems
       (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)
   * d/p/workarounds: Mark memory-monitor-psi tests as flaky
     (Mitigates: #1143197, #1143241)
 .
 glib2.0 (2.89.3-3) experimental; urgency=medium
 .
   [ Simon McVittie ]
   * Merge packaging from unstable
     - d/tests/1065022-futureproofing: Make the test pass more reliably,
       by ensuring that user-session-migration gets removed rather than
       making libglib2.0-0t64 be reinstalled
   * Drop patches added by 2.88.3-2, already part of 2.89.x
 .
 glib2.0 (2.89.3-2) experimental; urgency=medium
 .
   * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:
     Add patch from upstream to fix autopkgtest regression
   * d/changelog: Mention CVE-2026-15588, CVE-2026-58016 in the appropriate
     previous changelog entry
 .
 glib2.0 (2.89.3-1) experimental; urgency=medium
 .
   * New upstream release
   * debian/libglib2.0-0t64.symbols: Add new symbols
 .
 glib2.0 (2.89.2-1) experimental; urgency=medium
 .
   * New upstream release
     - Fixes possible integer underflow when parsing D-Bus introspection XML
       (CVE-2026-58016, Closes: #1141316)
     - Fixes resource exhaustion if a malicious client can contact a GDBusServer
       (CVE-2026-15588, Closes: #1142835)
   * d/p: Refresh patches
   * d/libglib2.0-0t64.symbols: Add new symbol
Checksums-Sha1:
 92f5c3d181b04bdf2bd126fd09f1c7d47d33d99b 4809 glib2.0_2.89.3-5.dsc
 af3872a6ab841fbd4618d11dcda02317a2fea995 145180 glib2.0_2.89.3-5.debian.tar.xz
 c14291048b10042d3ac029149f7e2baff3e6fac3 11637 glib2.0_2.89.3-5_source.buildinfo
Checksums-Sha256:
 d051d1b8f572ce65c8959d97d6433c2c685c6374fbf52a71d11fbadfe210e701 4809 glib2.0_2.89.3-5.dsc
 0fe2c3c9bf1a90376edb6ec3e4e602190b9df72c987cf3f3961e0a132d4aa5fb 145180 glib2.0_2.89.3-5.debian.tar.xz
 f57785267e300de810197e17b7dea6a05c60ee2aa8aa39ef041c0ea105c8208b 11637 glib2.0_2.89.3-5_source.buildinfo
Files:
 51909061d0431c875d197b9aa150a732 4809 libs optional glib2.0_2.89.3-5.dsc
 f7eb67b8b062f653390d1b9ca48502f8 145180 libs optional glib2.0_2.89.3-5.debian.tar.xz
 1677d300f3671162f2584bca30d78f2f 11637 libs optional glib2.0_2.89.3-5_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmqIYuYACgkQ5mx3Wuv+
bH1LlBAA0sAu2oTrdbp5reAEPTYrtgzuEM3RZvfZZ9PFjyXnlrBOalJ9O7Oz3Al3
47bIKAyAPsqt18QXthdpdSsBmQ4awj5Lo4rlS4P2tFHkZ3tnTQKTcTlHGGdm26d2
DUw6CV9hmcT/ipoVRey/yTUdYO/1u0lrqpRJ4B5qJu6HBJ3lnqp2Uj6f7FINEd5R
YMbKvhmierGBkSg84fmBHZluK8iSMZwdU7p/u9DZ2Wvp2CG5kyb2q2aWL/pwXrL1
XjKLQsFf9U7rOdtcT0ZusL8sfey6+u+v91wIyXUZ2xXsUru4RKbgRhXFfJQbGy7p
sxHKGNmRlggpj5RrWJvoREqPkkj79RzwQbkzr6CaiDIjaLriaAfXVyCkc7+N5JdG
HlVNUH3atAu5/Byi3tbai0ugZPiE/mzFe+1iM04vpvtY6e7tXGx12dKDna9nSeGI
G7wHhHZ1MyZRgNr54oemzxdXGb9Ez2bLdbR+1XPiQ/VK6ITSSMxWjCWPjwaFBUJT
SmPhiw9lCzetSFUfiDT0npX64ekOBBuNuqO3cZzvjc/ZJtW2VbNX1/EgNGfeSKZt
NhsmDpSgcYN1/tzAG5ln2ID12U9j2/pKx67Xs7IBrypWhotsGiKOQ0K3/6MAxuVS
35tdNnm64rNfW4+VEWbUnxRmLhGtYdfYgSzN0lRj3TT59S++hYM=
=Hr3H
-----END PGP SIGNATURE-----