CVE-2026-58016

A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

28 Jul 2026, 18:17

Type Values Removed Values Added
Summary (en) A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> or <arg>. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service. (en) A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.

27 Jul 2026, 17:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:46836 -

23 Jul 2026, 14:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:44481 -

21 Jul 2026, 04:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:42089 -

20 Jul 2026, 22:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:42063 -

20 Jul 2026, 19:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:42090 -

01 Jul 2026, 17:46

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2026-58016 - () https://access.redhat.com/security/cve/CVE-2026-58016 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2492257 - () https://bugzilla.redhat.com/show_bug.cgi?id=2492257 - Issue Tracking, Third Party Advisory
References () https://gitlab.gnome.org/GNOME/glib/-/issues/3932 - () https://gitlab.gnome.org/GNOME/glib/-/issues/3932 - Exploit, Issue Tracking, Third Party Advisory
CPE cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:a:gnome:glib:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
First Time Gnome
Gnome glib
Redhat enterprise Linux
Redhat

30 Jun 2026, 13:19

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-30 13:19

Updated : 2026-07-28 18:17


NVD link : CVE-2026-58016

Mitre link : CVE-2026-58016

CVE.ORG link : CVE-2026-58016


JSON object : View

Products Affected

gnome

  • glib

redhat

  • enterprise_linux
CWE
CWE-191

Integer Underflow (Wrap or Wraparound)