Home / mailingsPDF  

[USN-8794-1] GLib vulnerabilities

Posted on 21 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8794-1
September 21, 2026

glib2.0 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

GLib could be made to crash or expose sensitive information if it
received specially crafted input.

Software Description:
- glib2.0: GLib library of C routines

Details:

It was discovered that GLib's GDBus authentication mechanism failed to
enforce length limitations on data lines read from a client. An
unauthenticated attacker could exploit this to cause a denial of service
via resource exhaustion. (CVE-2026-15588)

It was discovered that the xdgmime library in GLib had a heap-based
buffer overflow. An attacker-controlled MIME magic file could cause an
out-of-bounds write on little-endian systems. (CVE-2026-16118)

It was discovered that GLib had an off-by-one error in the GVariant
serialiser. An attacker could use this to cause an out-of-bounds read,
leading to information disclosure or a denial of service.
(CVE-2026-58010)

It was discovered that GLib had an out-of-bounds read in GDateTime. An
attacker could use this to corrupt date output and cause a denial of
service. (CVE-2026-58011)

It was discovered that GLib's g_regex_replace() function had a buffer
over-read when used with the G_REGEX_RAW flag. An attacker could use
this to cause information disclosure or a denial of service.
(CVE-2026-58012)

It was discovered that GLib's GIOChannel had a buffer over-read when
using a custom line terminator. An attacker could use this to cause
information disclosure or a denial of service. (CVE-2026-58013)

It was discovered that GLib's GKeyFile had an off-by-one error when
loading a key file with an empty value. An attacker could use this to
cause an out-of-bounds access or a denial of service. (CVE-2026-58014)

It was discovered that GLib's DBUS_COOKIE_SHA1 authentication mechanism
failed to validate the cookie_context parameter. A malicious D-Bus
server could use this to read arbitrary files from the client.
(CVE-2026-58015)

It was discovered that GLib's D-Bus introspection XML parser had a
state confusion issue. An attacker could use this to cause an
out-of-bounds read and denial of service. (CVE-2026-58016)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
libglib2.0-0t64 2.88.0-1ubuntu0.1
libglib2.0-bin 2.88.0-1ubuntu0.1

Ubuntu 24.04 LTS
libglib2.0-0t64 2.80.0-6ubuntu3.9
libglib2.0-bin 2.80.0-6ubuntu3.9

Ubuntu 22.04 LTS
libglib2.0-0 2.72.4-0ubuntu2.10
libglib2.0-bin 2.72.4-0ubuntu2.10

Ubuntu 20.04 LTS
libglib2.0-0 2.64.6-1~ubuntu20.04.9+esm2
Available with Ubuntu Pro
libglib2.0-bin 2.64.6-1~ubuntu20.04.9+esm2
Available with Ubuntu Pro

Ubuntu 18.04 LTS
libglib2.0-0 2.56.4-0ubuntu0.18.04.9+esm6
Available with Ubuntu Pro
libglib2.0-bin 2.56.4-0ubuntu0.18.04.9+esm6
Available with Ubuntu Pro

Ubuntu 16.04 LTS
libglib2.0-0 2.48.2-0ubuntu4.8+esm6
Available with Ubuntu Pro
libglib2.0-bin 2.48.2-0ubuntu4.8+esm6
Available with Ubuntu Pro

Ubuntu 14.04 LTS
libglib2.0-0 2.40.2-0ubuntu1.1+esm8
Available with Ubuntu Pro
libglib2.0-bin 2.40.2-0ubuntu1.1+esm8
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8794-1
CVE-2026-15588, CVE-2026-16118, CVE-2026-58010, CVE-2026-58011,
CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015,
CVE-2026-58016

Package Information:
https://launchpad.net/ubuntu/+source/glib2.0/2.88.0-1ubuntu0.1
https://launchpad.net/ubuntu/+source/glib2.0/2.80.0-6ubuntu3.9
https://launchpad.net/ubuntu/+source/glib2.0/2.72.4-0ubuntu2.10

--===============6165243893603966135==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP