CVE-2026-15588

EUVD-2026-45939
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 10.69%
Debian logo
Debian Releases
Debian Product
Codename
glib2.0
bookworm
postponed
bookworm (security)
vulnerable
bullseye
postponed
bullseye (security)
vulnerable
forky
2.88.3-3
fixed
sid
2.89.3-5
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
glib2.0
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
glib2
RHEL 9
0:2.68.4-19.el9_8.9
fixed
glib2-devel
RHEL 9
0:2.68.4-19.el9_8.9
fixed
glib2-doc
RHEL 9
0:2.68.4-19.el9_8.9
fixed
glib2-static
RHEL 9
0:2.68.4-19.el9_8.9
fixed
glib2-tests
RHEL 9
0:2.68.4-19.el9_8.9
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
glib
Azure Linux 3.0
0:2.78.6-11.azl3
fixed