It was discovered that GLib's GDBus authentication mechanism failed to enforce length limitations on data lines read from a client. An unauthenticated attacker could exploit this to cause a denial of service via resource exhaustion. (CVE-2026-15588)
It was discovered that the xdgmime library in GLib had a heap-based buffer overflow. An attacker-controlled MIME magic file could cause an out-of-bounds write on little-endian systems. (CVE-2026-16118)
It was discovered that GLib had an off-by-one error in the GVariant serialiser. An attacker could use this to cause an out-of-bounds read, leading to information disclosure or a denial of service. (CVE-2026-58010)
It was discovered that GLib had an out-of-bounds read in GDateTime. An attacker could use this to corrupt date output and cause a denial of service. (CVE-2026-58011)
It was discovered that GLib's g_regex_replace() function had a buffer over-read when used with the G_REGEX_RAW flag. An attacker could use this to cause information disclosure or a denial of service. (CVE-2026-58012)
It was discovered that GLib's GIOChannel had a buffer over-read when using a custom line terminator. An attacker could use this to cause information disclosure or a denial of service. (CVE-2026-58013)
It was discovered that GLib's GKeyFile had an off-by-one error when loading a key file with an empty value. An attacker could use this to cause an out-of-bounds access or a denial of service. (CVE-2026-58014)
It was discovered that GLib's DBUS_COOKIE_SHA1 authentication mechanism failed to validate the cookie_context parameter. A malicious D-Bus server could use this to read arbitrary files from the client. (CVE-2026-58015)
It was discovered that GLib's D-Bus introspection XML parser had a state confusion issue. An attacker could use this to cause an out-of-bounds read and denial of service. (CVE-2026-58016)
2.72.4-0ubuntu2.102.80.0-6ubuntu3.92.88.0-1ubuntu0.12.40.2-0ubuntu1.1+esm82.48.2-0ubuntu4.8+esm62.56.4-0ubuntu0.18.04.9+esm62.64.6-1~ubuntu20.04.9+esm2