Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"
A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.
- EUVD-2026-40315
- ALSA-2026:49512
- ALSA-2026:55440
- ALSA-2026:57015
- ALSA-2026:61766
- openSUSE-SU-2026:21410-1
- RHSA-2026:49512
- RHSA-2026:55440
- RHSA-2026:57015
- RHSA-2026:61766
- RHSA-2026:65762
- RHSA-2026:65763
- RHSA-2026:65767
- RHSA-2026:65768
- RHSA-2026:65769
- RHSA-2026:65770
- RHSA-2026:65771
- RHSA-2026:65773
- RLSA-2026:49512
- RLSA-2026:55440
- Published
- Jun 30, 2026
- Updated
- Sep 30, 2026
- EPSS
- 0.9% · 57th percentile
- CWE
- CWE-126
Sign in to follow · You’ll be notified if a followed record enters KEV, gets an exploit or is updated.
Report tools
Action score
32
Monitor
Low priority for now.
- CVSS
- 32 / 40 · 8.2 / 10
- CISA KEV
- 0 / 30 · Not listed
- EPSS
- 0 / 30 · 0.9%
CISA SSVC decision
- Exploitation
- none
- Automatable
- no
- Technical impact
- partial
Vulnrichment: CISA's decision-tree inputs.
CNA vs NVD score
- NVD
- 8.2
- CNA · redhat
- 6.5
- 1.7 point gap
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
The score given by the assigning authority versus NVD’s independent score. A gap means the severity is contested.
Noroxi analysis
No Noroxi analysis for this record yet
We don't hand-write analysis for the hundreds of thousands of vulnerabilities in the database; that wouldn't be honest. For notable, high-impact vulnerabilities our team writes the mechanism, detection and remediation steps.
We use this product, ask for helpAffected systems
| Vendor | Product | CPE |
|---|---|---|
| gnome | glib | cpe:2.3:a:gnome:glib |
| redhat | enterprise linux | cpe:2.3:o:redhat:enterprise_linux |
Affected versions
NVD version ranges (for catalog products). Add the product to your stack with a version and matching uses these.
- gnome glibbefore 2.88.1
- redhat enterprise linux10.0
- redhat enterprise linux6.0
- redhat enterprise linux7.0
- redhat enterprise linux8.0
- redhat enterprise linux9.0
Versions reported by the vendor
Affected version ranges reported by the assigning authority (redhat). Independent of NVD's CPE analysis and usually ahead of it.
GNOME GLib
- before 2.88.1affected · semver
Red Hat Cert Manager support for Red Hat OpenShift release 1.19
- 1788348522 and laternot affected · rpm
- 1788348571 and laternot affected · rpm
- 1788348571 and laternot affected · rpm
- 1788348594 and laternot affected · rpm
Red Hat Cert Manager support for Red Hat OpenShift release 1.20
- 1790223279 and laternot affected · rpm
- 1790223719 and laternot affected · rpm
- 1790272426 and laternot affected · rpm
- 1790589998 and laternot affected · rpm
- 1790589912 and laternot affected · rpm
- 1790589914 and laternot affected · rpm
- 1790589855 and laternot affected · rpm
- 1790598593 and laternot affected · rpm
Red Hat Red Hat AI Inference Server 3.2
- 1790621714 and laternot affected · rpm
- 1790621718 and laternot affected · rpm
- 1790621713 and laternot affected · rpm
Red Hat Red Hat Discovery 2
- 1788205779 and laternot affected · rpm
- 1788206196 and laternot affected · rpm
Red Hat Red Hat Enterprise Linux 10
- 0:2.80.4-12.el10_2.21 and laternot affected · rpm
- all versionsaffected
Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support
- 0:2.80.4-4.el10_0.17 and laternot affected · rpm
Red Hat Red Hat Enterprise Linux 6
- all versionsaffected
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support
- 0:2.56.1-13.el7_9.1 and laternot affected · rpm
Red Hat Red Hat Enterprise Linux 8
- 0:2.70.1-9.el8_10 and laternot affected · rpm
- 0:2.56.4-177.el8_10 and laternot affected · rpm
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
- 0:2.56.4-10.el8_4.7 and laternot affected · rpm
Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
- 0:2.56.4-10.el8_4.7 and laternot affected · rpm
Package-level exposure
OSV and GitHub Advisory data: ecosystem, package and range. SBOM matching uses this table.
| Ecosystem | Package | Affected range | Fix |
|---|---|---|---|
| AlmaLinux:10 | glib2 | before 2.80.4-12.el10_2.21 | 2.80.4-12.el10_2.21 |
| AlmaLinux:10 | glib2-devel | before 2.80.4-12.el10_2.21 | 2.80.4-12.el10_2.21 |
| AlmaLinux:10 | glib2-doc | before 2.80.4-12.el10_2.21 | 2.80.4-12.el10_2.21 |
| AlmaLinux:10 | glib2-static | before 2.80.4-12.el10_2.21 | 2.80.4-12.el10_2.21 |
| AlmaLinux:10 | glib2-tests | before 2.80.4-12.el10_2.21 | 2.80.4-12.el10_2.21 |
| AlmaLinux:8 | glib2 | before 2.56.4-177.el8_10 | 2.56.4-177.el8_10 |
| AlmaLinux:8 | glib2-devel | before 2.56.4-177.el8_10 | 2.56.4-177.el8_10 |
| AlmaLinux:8 | glib2-doc | before 2.56.4-177.el8_10 | 2.56.4-177.el8_10 |
| AlmaLinux:8 | glib2-fam | before 2.56.4-177.el8_10 | 2.56.4-177.el8_10 |
| AlmaLinux:8 | glib2-static | before 2.56.4-177.el8_10 | 2.56.4-177.el8_10 |
| AlmaLinux:8 | glib2-tests | before 2.56.4-177.el8_10 | 2.56.4-177.el8_10 |
| AlmaLinux:8 | mingw32-glib2 | before 2.70.1-9.el8_10 | 2.70.1-9.el8_10 |
| AlmaLinux:8 | mingw32-glib2-static | before 2.70.1-9.el8_10 | 2.70.1-9.el8_10 |
| AlmaLinux:8 | mingw64-glib2 | before 2.70.1-9.el8_10 | 2.70.1-9.el8_10 |
| AlmaLinux:8 | mingw64-glib2-static | before 2.70.1-9.el8_10 | 2.70.1-9.el8_10 |
| AlmaLinux:9 | glib2 | before 2.68.4-19.el9_8.9 | 2.68.4-19.el9_8.9 |
| AlmaLinux:9 | glib2-devel | before 2.68.4-19.el9_8.9 | 2.68.4-19.el9_8.9 |
| AlmaLinux:9 | glib2-doc | before 2.68.4-19.el9_8.9 | 2.68.4-19.el9_8.9 |
| AlmaLinux:9 | glib2-static | before 2.68.4-19.el9_8.9 | 2.68.4-19.el9_8.9 |
| AlmaLinux:9 | glib2-tests | before 2.68.4-19.el9_8.9 | 2.68.4-19.el9_8.9 |
| Debian:12 | glib2.0 | all versions | — |
| Debian:13 | glib2.0 | before 2.84.4-3~deb13u4 | 2.84.4-3~deb13u4 |
| Debian:14 | glib2.0 | before 2.88.1-2 | 2.88.1-2 |
| openSUSE:Leap 16.0 | glib2 | before 2.84.4-160000.4.1 | 2.84.4-160000.4.1 |
+96
Same product
gnome: all recordsOther highest-scoring records for the same primary product.
- CVE-2019-12450file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is 40Plan
- CVE-2018-16428In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.40Plan
- CVE-2025-14087Glib: glib: buffer underflow in gvariant parser leads to heap corruption39Monitor
- CVE-2024-52533gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not suf39Monitor
- CVE-2026-58016Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"36Monitor
- CVE-2026-58014Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"34Monitor
Remediation
Which version to upgrade to
Fix versions compiled from the vendor, package registries and Microsoft. Verify the vendor's note before upgrading.
| Product / package | Fixed version | Source |
|---|---|---|
| GNOME GLib | 2.88.1 | Vendor (CNA) |
| almalinux:glib2 | 2.68.4-19.el9_8.9 · AlmaLinux:9 | Package registry (OSV) |
| almalinux:glib2-devel | 2.68.4-19.el9_8.9 · AlmaLinux:9 | Package registry (OSV) |
| almalinux:glib2-doc | 2.68.4-19.el9_8.9 · AlmaLinux:9 | Package registry (OSV) |
| almalinux:glib2-fam | 2.56.4-177.el8_10 · AlmaLinux:8 | Package registry (OSV) |
| almalinux:glib2-static | 2.68.4-19.el9_8.9 · AlmaLinux:9 | Package registry (OSV) |
| almalinux:glib2-tests | 2.68.4-19.el9_8.9 · AlmaLinux:9 | Package registry (OSV) |
| almalinux:mingw32-glib2 | 2.70.1-9.el8_10 · AlmaLinux:8 | Package registry (OSV) |
| almalinux:mingw32-glib2-static | 2.70.1-9.el8_10 · AlmaLinux:8 | Package registry (OSV) |
| almalinux:mingw64-glib2 | 2.70.1-9.el8_10 · AlmaLinux:8 | Package registry (OSV) |
| almalinux:mingw64-glib2-static | 2.70.1-9.el8_10 · AlmaLinux:8 | Package registry (OSV) |
| debian:glib2.0 | 2.84.4-3~deb13u4 · Debian:13 | Package registry (OSV) |
| opensuse:glib2 | 2.84.4-160000.4.1 · openSUSE:Leap 16.0 | Package registry (OSV) |
| opensuse:glib2-doc | 2.84.4-160000.4.1 · openSUSE:Leap 16.0 | Package registry (OSV) |
| red hat:glib2-debuginfo | 0:2.68.4-19.el9_8.9 · Red Hat:enterprise_linux:9::appstream | Package registry (OSV) |
| red hat:glib2-debugsource | 0:2.68.4-19.el9_8.9 · Red Hat:enterprise_linux:9::appstream | Package registry (OSV) |
| red hat:glib2-devel | 0:2.68.4-19.el9_8.9 · Red Hat:enterprise_linux:9::appstream | Package registry (OSV) |
| red hat:glib2-devel-debuginfo | 0:2.68.4-19.el9_8.9 · Red Hat:enterprise_linux:9::appstream | Package registry (OSV) |
| red hat:glib2-doc | 0:2.68.4-19.el9_8.9 · Red Hat:enterprise_linux:9::appstream | Package registry (OSV) |
| red hat:mingw-glib2 | 0:2.70.1-9.el8_10 · Red Hat:enterprise_linux:8::crb | Package registry (OSV) |
| red hat:mingw32-glib2 | 0:2.70.1-9.el8_10 · Red Hat:enterprise_linux:8::crb | Package registry (OSV) |
| red hat:mingw32-glib2-debuginfo | 0:2.70.1-9.el8_10 · Red Hat:enterprise_linux:8::crb | Package registry (OSV) |
| red hat:mingw32-glib2-static | 0:2.70.1-9.el8_10 · Red Hat:enterprise_linux:8::crb | Package registry (OSV) |
| red hat:mingw64-glib2 | 0:2.70.1-9.el8_10 · Red Hat:enterprise_linux:8::crb | Package registry (OSV) |
| red hat:mingw64-glib2-debuginfo | 0:2.70.1-9.el8_10 · Red Hat:enterprise_linux:8::crb | Package registry (OSV) |
| red hat:mingw64-glib2-static | 0:2.70.1-9.el8_10 · Red Hat:enterprise_linux:8::crb | Package registry (OSV) |
| rocky linux:glib2 | 0:2.68.4-19.el9_8.9 · Rocky Linux:9 | Package registry (OSV) |
| rocky linux:mingw-glib2 | 0:2.70.1-9.el8_10 · Rocky Linux:8 | Package registry (OSV) |
| suse:glib2 | 2.84.4-160000.4.1 · SUSE:Linux Enterprise Server 16.0 | Package registry (OSV) |
| suse:glib2-doc | 2.84.4-160000.4.1 · SUSE:Linux Enterprise Server 16.0 | Package registry (OSV) |
Exploit status
No known public exploit
No public exploit has been observed yet. That doesn't mean you're safe, only that the bar is a little higher.
Research context
For pentesters and researchers: attack profile, score disagreement, timeline, patch commits, credits, variant and chain candidates, bug bounty scope. All derived from existing data; no exploit code.
Timeline
From publication to today: proof of concept, Metasploit module, CISA KEV and fix record. Dates are as reported by the sources.
No dated events beyond publication.
FIRST EPSS daily score; only changes of 0.01 or more are recorded (step chart).
Patch and commit links
Commit, PR and diff links among the references. A starting point for patch-diffing and variant hunting; fixes, not exploits.
No commit or PR link among the references.
Credits
All researchersFinders, reporters and analysts named in the CNA record. Click a name for that researcher’s other records.
Variant candidates
Same product, same weakness class, within 18 months. If the patch missed the root cause, the sibling bug is here.
- CVE-2026-580100 days apartGlib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()32Monitor
- CVE-2026-580120 days apartGlib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()32Monitor
Chain candidates
An authentication bypass and a privilege-requiring bug in the same product, published close together: combined they may become an unauthenticated path.
—
Bug bounty scope
No known public program.
Source: bounty-targets-data (public HackerOne, Bugcrowd, Intigriti, YesWeHack listings).
Technical details
Attack conditions
- Anyone who can reach it over the internet can trigger it.
- No account or password is required.
- No user action is required.
- No special conditions are required; it is repeatable.
If successful
- Confidentiality
- low · data can be read
- Integrity
- none
- Availability
- high · the service can be disrupted
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality impact
- Low
- Integrity impact
- None
- Availability impact
- High
Weakness class (CWE)
CWE-126 · Buffer Over-readCVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
nvd-primary
Attack context
MITRE CAPEC attack patterns and ATT&CK techniques for this weakness class (CWE). A starting point for detection rules and threat hunting.
MITRE has no CAPEC/ATT&CK mapping for this CWE.
Change log
- Fix✗ → ✓
- SSVC exploitation— → none
For records you follow, these changes also arrive as notifications. →
References
- access.redhat.com/errata/RHSA-2026:49512
- access.redhat.com/errata/RHSA-2026:55440
- access.redhat.com/errata/RHSA-2026:57015
- access.redhat.com/errata/RHSA-2026:58981
- access.redhat.com/errata/RHSA-2026:61766
- access.redhat.com/errata/RHSA-2026:61783
- access.redhat.com/errata/RHSA-2026:63135
- access.redhat.com/errata/RHSA-2026:63138
- access.redhat.com/errata/RHSA-2026:63140
- access.redhat.com/errata/RHSA-2026:65762
- access.redhat.com/errata/RHSA-2026:65763
- access.redhat.com/errata/RHSA-2026:65767
- access.redhat.com/errata/RHSA-2026:65768
- access.redhat.com/errata/RHSA-2026:65769
- access.redhat.com/errata/RHSA-2026:65770
- access.redhat.com/errata/RHSA-2026:65771
- access.redhat.com/errata/RHSA-2026:65773
- access.redhat.com/errata/RHSA-2026:66018
- access.redhat.com/errata/RHSA-2026:72394
- access.redhat.com/errata/RHSA-2026:72395
Vendor advisories and official records. Exploit/PoC links are deliberately left out.