CVE-2026-58015
EUVD-2026-4031830.06.2026, 13:19
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gnome | glib | 𝑥 < 2.88.1 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| glib2.0 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| glib2 |
| ||||||||||||
| glib2-devel |
| ||||||||||||
| glib2-doc |
| ||||||||||||
| glib2-fam |
| ||||||||||||
| glib2-static |
| ||||||||||||
| glib2-tests |
| ||||||||||||
| mingw32-glib2 |
| ||||||||||||
| mingw32-glib2-static |
| ||||||||||||
| mingw64-glib2 |
| ||||||||||||
| mingw64-glib2-static |
|
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| glib2 |
| ||
| glib2-debuginfo |
| ||
| glib2-debugsource |
| ||
| glib2-devel |
| ||
| glib2-devel-debuginfo |
| ||
| glib2-doc |
| ||
| glib2-static |
| ||
| glib2-tests |
| ||
| glib2-tests-debuginfo |
|
Vulnerability Media Exposure
References