#1142835 glib2.0: CVE-2026-15588

Package:
src:glib2.0
Source:
src:glib2.0
Submitter:
Salvatore Bonaccorso
Date:
2026-08-21 15:17:03 UTC
Severity:
normal
Tags:
#1142835#5
Date:
2026-07-26 19:56:37 UTC
From:
To:
Hi,

The following vulnerability was published for glib2.0.

CVE-2026-15588[0]:
| A denial-of-service and resource exhaustion vulnerability exists
| within the `GDBus` component of GLib. The `gdbusauth` authentication
| mechanism fails to enforce proper length limitations on data lines
| read from a client. An unauthenticated local or remote attacker can
| exploit this lack of input validation by sending excessively long
| streams of data, causing the application to consume massive amounts
| of system memory and CPU, potentially leading to a crash or system
| hang.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-15588
https://www.cve.org/CVERecord?id=CVE-2026-15588
[1] https://gitlab.gnome.org/GNOME/glib/-/issues/3985
[2] https://gitlab.gnome.org/GNOME/glib/-/commit/4235f7b42ba51d6fdb4abd7c4276031802f39834

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1142835#10
Date:
2026-07-30 14:03:34 UTC
From:
To:
Control: fixed -1 2.89.2-1

I believe we'll fix this for Unstable by uploading the new major
release 2.89.3 (equivalent to GNOME 51 Beta) in the next few days.

Thank you,
Jeremy Bícha

#1142835#19
Date:
2026-07-30 18:21:21 UTC
From:
To:
Hi Jeremy,

Yes that makes perfectly sense. I think the issue can be considered as
well no-dsa and does not need a dedicated DSA, but maybe issues open
yet for trixie could be included in an upcoming point release.

Regards,
Salvatore

#1142835#26
Date:
2026-08-01 00:20:12 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
glib2.0, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142835@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon McVittie <smcv@debian.org> (supplier of updated glib2.0 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 31 Jul 2026 21:13:54 +0100
Source: glib2.0
Architecture: source
Version: 2.88.3-1
Distribution: unstable
Urgency: medium
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Closes: 1142835
Changes:
 glib2.0 (2.88.3-1) unstable; urgency=medium
 .
   * New upstream stable release
     - Fixes resource exhaustion if a malicious client can contact a
       GDBusServer (CVE-2026-15588, Closes: #1142835)
   * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:
     Add patch from upstream to fix autopkgtest regression
   * d/control, d/gbp.conf: Use debian/forky branch
Checksums-Sha1:
 1a3b46a526764b86c09f3288e97daee9d10130b1 4939 glib2.0_2.88.3-1.dsc
 f844ba1b1075bec1f80d3069e3f9437dfc86b42d 666552 glib2.0_2.88.3.orig-unicode-data.tar.xz
 1831d83abab126895df34fe04cf3e86dee5d8c44 5794356 glib2.0_2.88.3.orig.tar.xz
 e12e44f1782d6566e982909e5521fd56871628cf 143208 glib2.0_2.88.3-1.debian.tar.xz
 4a9f2fa4368cd832a1399f5d5b49702a786f8f26 7243 glib2.0_2.88.3-1_source.buildinfo
Checksums-Sha256:
 6a1bb48796e67c2366582514874f08a8704a442bfc0f66dcb54be6580400a7ce 4939 glib2.0_2.88.3-1.dsc
 4b55352323696c72187f855981ed1f7d1594a53f257f7803a928749cab9f9f44 666552 glib2.0_2.88.3.orig-unicode-data.tar.xz
 ab24d24e698dfa1e408b7bcdb508f4aafc906185a8b8ce72fdf79bbbdc9b383b 5794356 glib2.0_2.88.3.orig.tar.xz
 5238a5b569b3d30ddee47191a90da68e409ee084814f6eb9b3938351ec1020b7 143208 glib2.0_2.88.3-1.debian.tar.xz
 e89651592c1a656e0425889097c229488555b4e222f2fffbe4a431074c3c3629 7243 glib2.0_2.88.3-1_source.buildinfo
Files:
 501c6587dcaf624a7f47a151a10a81e7 4939 libs optional glib2.0_2.88.3-1.dsc
 4e5631558a56f2ddc14b8f431aef3b12 666552 libs optional glib2.0_2.88.3.orig-unicode-data.tar.xz
 b61c04cfbf55b0d24fbe64e4ac9e9d56 5794356 libs optional glib2.0_2.88.3.orig.tar.xz
 c69c8b3a057d6b191e50a105d6ea95cb 143208 libs optional glib2.0_2.88.3-1.debian.tar.xz
 fbeb95cae38b99a8b98e1ef8bf0ebe64 7243 libs optional glib2.0_2.88.3-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEegc60a5pT6Jb/2LlI1wJnT6zMHYFAmptMbcACgkQI1wJnT6z
MHZW3w/+OOt0K8TgsAodlH+/lgEc7hj39zTXq5JTaoUqhNNm2wJcgow3/ZDK9hAq
BwmTLQpAv5zyi9Vzy83duJV2assYZav8bcJXLPRhHPnkIK3tQSBX6ft//9YhBgf/
+s6njCwsRZQq9vCMxkYexA0A2lx0m5m0+B5721iTx+vxtcajL8zzLDO0rc56sTTN
NhkowSXgo2OwQ3CEqvJxMoQXirqV82EKodoFG7Fagmr++4PaDe+wMNHi6WJmRNzv
Xs2HmZnjviA2RJWHQ/XmVcUgPCZxIJvCoYJsyH/Yt8GpU7UHyrUluwmVNzYpI1ON
cn9muxnlBvoWy5bCH92VzqCF+y3Yep37NH8W40fe4MiDgF1rjgqe3DgNS1tHU8BS
vhxN68bFpI3oKyTYS8CuEB8TDxj/tuO8IADPRNrRTXEcV5jXvBcjtmjPA4pvP7mH
Myk1ijDXFNLQMBUPrsdksN7eyeigk4mXB2aa8Oo+m4HI7JxZKbRiwq6kfSUhLzdv
Mix5p0gcG7H6VfV9oJUovHLMVdKiIkCt8HWx2rTMffk8+FJyP7CDdaqmM/HHVKoL
mClB5H3LsrPt4CgvIYwuxjsdrIl/eJMFUaRXXPwdnSvD1/C/BAgdggY7gceBK3jr
iR//bP+x9pYR3S9bPfr6rUzqeRXvQqgbSv/IOmRUd8HHvYyTQ6g=
=83ZE
-----END PGP SIGNATURE-----

#1142835#31
Date:
2026-08-21 15:14:28 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
glib2.0, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142835@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jeremy Bícha <jbicha@ubuntu.com> (supplier of updated glib2.0 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 21 Aug 2026 16:37:11 +0200
Source: glib2.0
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 2.89.3-5
Distribution: unstable
Urgency: medium
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Jeremy Bícha <jbicha@ubuntu.com>
Closes: 1141316 1142717 1142835
Changes:
 glib2.0 (2.89.3-5) unstable; urgency=medium
 .
   * Release to unstable
 .
 glib2.0 (2.89.3-4) experimental; urgency=medium
 .
   * Merge from unstable
     - d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,
       d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:
       Add patches from upstream (to be released in 2.89.4) to address
       an out-of-bounds write if parsing a crafted XDG MIME magic file,
       and fix a related test failure on minimal systems
       (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)
   * d/p/workarounds: Mark memory-monitor-psi tests as flaky
     (Mitigates: #1143197, #1143241)
 .
 glib2.0 (2.89.3-3) experimental; urgency=medium
 .
   [ Simon McVittie ]
   * Merge packaging from unstable
     - d/tests/1065022-futureproofing: Make the test pass more reliably,
       by ensuring that user-session-migration gets removed rather than
       making libglib2.0-0t64 be reinstalled
   * Drop patches added by 2.88.3-2, already part of 2.89.x
 .
 glib2.0 (2.89.3-2) experimental; urgency=medium
 .
   * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:
     Add patch from upstream to fix autopkgtest regression
   * d/changelog: Mention CVE-2026-15588, CVE-2026-58016 in the appropriate
     previous changelog entry
 .
 glib2.0 (2.89.3-1) experimental; urgency=medium
 .
   * New upstream release
   * debian/libglib2.0-0t64.symbols: Add new symbols
 .
 glib2.0 (2.89.2-1) experimental; urgency=medium
 .
   * New upstream release
     - Fixes possible integer underflow when parsing D-Bus introspection XML
       (CVE-2026-58016, Closes: #1141316)
     - Fixes resource exhaustion if a malicious client can contact a GDBusServer
       (CVE-2026-15588, Closes: #1142835)
   * d/p: Refresh patches
   * d/libglib2.0-0t64.symbols: Add new symbol
Checksums-Sha1:
 92f5c3d181b04bdf2bd126fd09f1c7d47d33d99b 4809 glib2.0_2.89.3-5.dsc
 af3872a6ab841fbd4618d11dcda02317a2fea995 145180 glib2.0_2.89.3-5.debian.tar.xz
 c14291048b10042d3ac029149f7e2baff3e6fac3 11637 glib2.0_2.89.3-5_source.buildinfo
Checksums-Sha256:
 d051d1b8f572ce65c8959d97d6433c2c685c6374fbf52a71d11fbadfe210e701 4809 glib2.0_2.89.3-5.dsc
 0fe2c3c9bf1a90376edb6ec3e4e602190b9df72c987cf3f3961e0a132d4aa5fb 145180 glib2.0_2.89.3-5.debian.tar.xz
 f57785267e300de810197e17b7dea6a05c60ee2aa8aa39ef041c0ea105c8208b 11637 glib2.0_2.89.3-5_source.buildinfo
Files:
 51909061d0431c875d197b9aa150a732 4809 libs optional glib2.0_2.89.3-5.dsc
 f7eb67b8b062f653390d1b9ca48502f8 145180 libs optional glib2.0_2.89.3-5.debian.tar.xz
 1677d300f3671162f2584bca30d78f2f 11637 libs optional glib2.0_2.89.3-5_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmqIYuYACgkQ5mx3Wuv+
bH1LlBAA0sAu2oTrdbp5reAEPTYrtgzuEM3RZvfZZ9PFjyXnlrBOalJ9O7Oz3Al3
47bIKAyAPsqt18QXthdpdSsBmQ4awj5Lo4rlS4P2tFHkZ3tnTQKTcTlHGGdm26d2
DUw6CV9hmcT/ipoVRey/yTUdYO/1u0lrqpRJ4B5qJu6HBJ3lnqp2Uj6f7FINEd5R
YMbKvhmierGBkSg84fmBHZluK8iSMZwdU7p/u9DZ2Wvp2CG5kyb2q2aWL/pwXrL1
XjKLQsFf9U7rOdtcT0ZusL8sfey6+u+v91wIyXUZ2xXsUru4RKbgRhXFfJQbGy7p
sxHKGNmRlggpj5RrWJvoREqPkkj79RzwQbkzr6CaiDIjaLriaAfXVyCkc7+N5JdG
HlVNUH3atAu5/Byi3tbai0ugZPiE/mzFe+1iM04vpvtY6e7tXGx12dKDna9nSeGI
G7wHhHZ1MyZRgNr54oemzxdXGb9Ez2bLdbR+1XPiQ/VK6ITSSMxWjCWPjwaFBUJT
SmPhiw9lCzetSFUfiDT0npX64ekOBBuNuqO3cZzvjc/ZJtW2VbNX1/EgNGfeSKZt
NhsmDpSgcYN1/tzAG5ln2ID12U9j2/pKx67Xs7IBrypWhotsGiKOQ0K3/6MAxuVS
35tdNnm64rNfW4+VEWbUnxRmLhGtYdfYgSzN0lRj3TT59S++hYM=
=Hr3H
-----END PGP SIGNATURE-----