<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:03:54 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:55440 — Moderate: glib2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:55440</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: glib2, AlmaLinux:9: glib2-devel, AlmaLinux:9: glib2-doc, AlmaLinux:9: glib2-static, AlmaLinux:9: glib2-tests&lt;/p&gt;
&lt;p&gt;GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() (CVE-2026-58010)
  * glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime (CVE-2026-58011)
  * glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() (CVE-2026-58012)
  * glib: buffer over-read in glib/giochannel.c via &amp;#34;g_io_channel_read_line_backend&amp;#34; (CVE-2026-58013)
  * glib: off-by-one error in glib/gkeyfile.c via &amp;#34;g_key_file_get_locale_string_list&amp;#34; (CVE-2026-58014)
  * glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive (CVE-2026-58015)
  * GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering (CVE-2026-15588)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: glib2, AlmaLinux:9: glib2-devel, AlmaLinux:9: glib2-doc, AlmaLinux:9: glib2-static, AlmaLinux:9: glib2-tests&lt;/p&gt;
&lt;p&gt;GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() (CVE-2026-58010)
  * glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime (CVE-2026-58011)
  * glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() (CVE-2026-58012)
  * glib: buffer over-read in glib/giochannel.c via &amp;#34;g_io_channel_read_line_backend&amp;#34; (CVE-2026-58013)
  * glib: off-by-one error in glib/gkeyfile.c via &amp;#34;g_key_file_get_locale_string_list&amp;#34; (CVE-2026-58014)
  * glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive (CVE-2026-58015)
  * GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering (CVE-2026-15588)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:55440</guid>
    </item>
    <item>
      <title>bdu:2026-10233</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-10233</link>
      <description>bdu:2026-10233</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-10233</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-15588</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-15588</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: glib, Alpaquita:25: glib, Alpaquita:stream: glib&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: glib, Alpaquita:25: glib, Alpaquita:stream: glib&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-15588</guid>
    </item>
    <item>
      <title>EUVD-2026-382032</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-382032</link>
      <description>EUVD-2026-382032</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-382032</guid>
    </item>
    <item>
      <title>fkie_cve-2026-15588</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-15588</link>
      <description>&lt;p&gt;A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-15588</guid>
    </item>
    <item>
      <title>GHSA-hrq7-vgh7-p534</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hrq7-vgh7-p534</link>
      <description>&lt;p&gt;A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hrq7-vgh7-p534</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-15588 — Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-15588</link>
      <description>msrc_CVE-2026-15588</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-15588</guid>
    </item>
    <item>
      <title>OESA-2026-3241 — glib2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3241</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: glib2&lt;/p&gt;
&lt;p&gt;GLib is a bundle of three (formerly five) low-level system libraries written in C and developed mainly by GNOME. GLib&amp;amp;amp;apos;s code was separated from GTK, so it can be used by software other than GNOME and has been developed in parallel ever since.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.(CVE-2026-15588)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: glib2&lt;/p&gt;
&lt;p&gt;GLib is a bundle of three (formerly five) low-level system libraries written in C and developed mainly by GNOME. GLib&amp;amp;amp;apos;s code was separated from GTK, so it can be used by software other than GNOME and has been developed in parallel ever since.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.(CVE-2026-15588)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3241</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11415-1 — gio-branding-upstream-2.88.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11415-1</link>
      <description>&lt;p&gt;gio-branding-upstream-2.88.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;gio-branding-upstream-2.88.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11415-1</guid>
    </item>
    <item>
      <title>RHSA-2026:39985 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:39985</link>
      <description>&lt;p&gt;GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:39985</guid>
    </item>
    <item>
      <title>RLSA-2026:55440 — Moderate: glib2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:55440</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: glib2&lt;/p&gt;
&lt;p&gt;GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() (CVE-2026-58010)&lt;/p&gt;
&lt;p&gt;* glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime (CVE-2026-58011)&lt;/p&gt;
&lt;p&gt;* glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() (CVE-2026-58012)&lt;/p&gt;
&lt;p&gt;* glib: buffer over-read in glib/giochannel.c via &amp;#34;g_io_channel_read_line_backend&amp;#34; (CVE-2026-58013)&lt;/p&gt;
&lt;p&gt;* glib: off-by-one error in glib/gkeyfile.c via &amp;#34;g_key_file_get_locale_string_list&amp;#34; (CVE-2026-58014)&lt;/p&gt;
&lt;p&gt;* glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive (CVE-2026-58015)&lt;/p&gt;
&lt;p&gt;* GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering (CVE-2026-15588)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: glib2&lt;/p&gt;
&lt;p&gt;GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() (CVE-2026-58010)&lt;/p&gt;
&lt;p&gt;* glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime (CVE-2026-58011)&lt;/p&gt;
&lt;p&gt;* glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() (CVE-2026-58012)&lt;/p&gt;
&lt;p&gt;* glib: buffer over-read in glib/giochannel.c via &amp;#34;g_io_channel_read_line_backend&amp;#34; (CVE-2026-58013)&lt;/p&gt;
&lt;p&gt;* glib: off-by-one error in glib/gkeyfile.c via &amp;#34;g_key_file_get_locale_string_list&amp;#34; (CVE-2026-58014)&lt;/p&gt;
&lt;p&gt;* glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive (CVE-2026-58015)&lt;/p&gt;
&lt;p&gt;* GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering (CVE-2026-15588)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:55440</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23880-1 — Security update for glib2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23880-1</link>
      <description>&lt;p&gt;Security update for glib2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for glib2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23880-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-15588</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-15588</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: glib2.0, Ubuntu:Pro:16.04:LTS: glib2.0, Ubuntu:Pro:18.04:LTS: glib2.0, Ubuntu:Pro:20.04:LTS: glib2.0, Ubuntu:22.04:LTS: glib2.0, Ubuntu:24.04:LTS: glib2.0, Ubuntu:26.04:LTS: glib2.0&lt;/p&gt;
&lt;p&gt;A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: glib2.0, Ubuntu:Pro:16.04:LTS: glib2.0, Ubuntu:Pro:18.04:LTS: glib2.0, Ubuntu:Pro:20.04:LTS: glib2.0, Ubuntu:22.04:LTS: glib2.0, Ubuntu:24.04:LTS: glib2.0, Ubuntu:26.04:LTS: glib2.0&lt;/p&gt;
&lt;p&gt;A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-15588</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2866 — Red Hat Enterprise Linux (glib2): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2866</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux (glib2) ausnutzen, um einen Denial of Service Angriff durchzuführen und um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux (glib2) ausnutzen, um einen Denial of Service Angriff durchzuführen und um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2866</guid>
    </item>
  </channel>
</rss>
