CVE-2026-58015
EUVD-2026-4031830.06.2026, 13:19
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gnome | glib | 𝑥 < 2.88.1 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Red Hat Enterprise Linux Releases
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| glib2 |
| ||
| glib2-debuginfo |
| ||
| glib2-debugsource |
| ||
| glib2-devel |
| ||
| glib2-devel-debuginfo |
| ||
| glib2-doc |
| ||
| glib2-static |
| ||
| glib2-tests |
| ||
| glib2-tests-debuginfo |
|