#1142835 glib2.0: CVE-2026-15588

Package:
src:glib2.0
Source:
src:glib2.0
Submitter:
Salvatore Bonaccorso
Date:
2026-07-26 19:59:02 UTC
Severity:
normal
Tags:
#1142835#5
Date:
2026-07-26 19:56:37 UTC
From:
To:
Hi,

The following vulnerability was published for glib2.0.

CVE-2026-15588[0]:
| A denial-of-service and resource exhaustion vulnerability exists
| within the `GDBus` component of GLib. The `gdbusauth` authentication
| mechanism fails to enforce proper length limitations on data lines
| read from a client. An unauthenticated local or remote attacker can
| exploit this lack of input validation by sending excessively long
| streams of data, causing the application to consume massive amounts
| of system memory and CPU, potentially leading to a crash or system
| hang.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-15588
https://www.cve.org/CVERecord?id=CVE-2026-15588
[1] https://gitlab.gnome.org/GNOME/glib/-/issues/3985
[2] https://gitlab.gnome.org/GNOME/glib/-/commit/4235f7b42ba51d6fdb4abd7c4276031802f39834

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore