<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:01:41.727775+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:55440</id>
    <title>ALSA-2026:55440 — Moderate: glib2 security update</title>
    <updated>2026-10-02T13:01:42.099687+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: glib2, AlmaLinux:9: glib2-devel, AlmaLinux:9: glib2-doc, AlmaLinux:9: glib2-static, AlmaLinux:9: glib2-tests</p>
<p>GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.</p>
<p>Security Fix(es):</p>
<p>* glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() (CVE-2026-58010)
  * glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime (CVE-2026-58011)
  * glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() (CVE-2026-58012)
  * glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" (CVE-2026-58013)
  * glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" (CVE-2026-58014)
  * glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive (CVE-2026-58015)
  * GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering (CVE-2026-15588)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:55440"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-10233</id>
    <title>bdu:2026-10233</title>
    <updated>2026-10-02T13:01:42.099808+00:00</updated>
    <content>bdu:2026-10233</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-10233"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-15588</id>
    <title>BELL-CVE-2026-15588</title>
    <updated>2026-10-02T13:01:42.099827+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: glib, Alpaquita:25: glib, Alpaquita:stream: glib</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-15588"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-382032</id>
    <title>EUVD-2026-382032</title>
    <updated>2026-10-02T13:01:42.099850+00:00</updated>
    <content>EUVD-2026-382032</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-382032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-15588</id>
    <title>fkie_cve-2026-15588</title>
    <updated>2026-10-02T13:01:42.099862+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-15588"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hrq7-vgh7-p534</id>
    <title>GHSA-hrq7-vgh7-p534</title>
    <updated>2026-10-02T13:01:42.099884+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hrq7-vgh7-p534"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-15588</id>
    <title>msrc_CVE-2026-15588 — Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering</title>
    <updated>2026-10-02T13:01:42.099900+00:00</updated>
    <content>msrc_CVE-2026-15588</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-15588"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3241</id>
    <title>OESA-2026-3241 — glib2 security update</title>
    <updated>2026-10-02T13:01:42.099917+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: glib2</p>
<p>GLib is a bundle of three (formerly five) low-level system libraries written in C and developed mainly by GNOME. GLib&amp;amp;apos;s code was separated from GTK, so it can be used by software other than GNOME and has been developed in parallel ever since.

Security Fix(es):</p>
<p>A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.(CVE-2026-15588)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3241"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11415-1</id>
    <title>openSUSE-SU-2026:11415-1 — gio-branding-upstream-2.88.3-1.1 on GA media</title>
    <updated>2026-10-02T13:01:42.099941+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gio-branding-upstream-2.88.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11415-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:39985</id>
    <title>RHSA-2026:39985 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-02T13:01:42.099957+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:39985"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:55440</id>
    <title>RLSA-2026:55440 — Moderate: glib2 security update</title>
    <updated>2026-10-02T13:01:42.099974+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: glib2</p>
<p>GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.</p>
<p>Security Fix(es):</p>
<p>* glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() (CVE-2026-58010)</p>
<p>* glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime (CVE-2026-58011)</p>
<p>* glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() (CVE-2026-58012)</p>
<p>* glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" (CVE-2026-58013)</p>
<p>* glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" (CVE-2026-58014)</p>
<p>* glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive (CVE-2026-58015)</p>
<p>* GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering (CVE-2026-15588)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:55440"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23880-1</id>
    <title>SUSE-SU-2026:23880-1 — Security update for glib2</title>
    <updated>2026-10-02T13:01:42.100004+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for glib2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23880-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-15588</id>
    <title>UBUNTU-CVE-2026-15588</title>
    <updated>2026-10-02T13:01:42.100019+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: glib2.0, Ubuntu:Pro:16.04:LTS: glib2.0, Ubuntu:Pro:18.04:LTS: glib2.0, Ubuntu:Pro:20.04:LTS: glib2.0, Ubuntu:22.04:LTS: glib2.0, Ubuntu:24.04:LTS: glib2.0, Ubuntu:26.04:LTS: glib2.0</p>
<p>A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-15588"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2866</id>
    <title>WID-SEC-W-2026-2866 — Red Hat Enterprise Linux (glib2): Mehrere Schwachstellen</title>
    <updated>2026-10-02T13:01:42.100047+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux (glib2) ausnutzen, um einen Denial of Service Angriff durchzuführen und um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2866"/>
  </entry>
</feed>
