[CLSA-2026:1785760071] glib2: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-03 12:28:05 UTC
Description:
- CVE-2026-58010: fix one-byte heap over-read in gvs_tuple_is_normal() by changing the offset bounds check from '>' to '>=' (glib/gvariant-serialiser.c) - CVE-2026-58011: validate the days field in g_date_time_add_full() to prevent an out-of-bounds read in g_date_time_get_ymd() (glib/gdatetime.c) - CVE-2026-58012: fix buffer over-read in g_regex_replace() with G_REGEX_RAW by splitting UTF-8 vs raw code paths in string_append() (glib/gregex.c) - CVE-2026-58013: fix out-of-bounds read in g_io_channel_read_line_backend() by bounding memcmp() length to the remaining buffer (glib/giochannel.c)
Updated packages:
  • glib2-2.68.4-6.el9.tuxcare.els9.i686.rpm
    sha:2af395b7c661b3cb26596f8f34eca585cf71f24b5629fe17c83b63eedb6d824c
  • glib2-2.68.4-6.el9.tuxcare.els9.x86_64.rpm
    sha:ca97ca0a7f84abbceb778c2523f384daca910ba783f33ca9bc52f4c4a0294451
  • glib2-devel-2.68.4-6.el9.tuxcare.els9.i686.rpm
    sha:dc44e1fa16dddc57424b956d4f587e77848bf409610cecfc1021ead3407c6dcf
  • glib2-devel-2.68.4-6.el9.tuxcare.els9.x86_64.rpm
    sha:77b06a4e88b4234d0c79eedd0c5796e869351a215a47cbe435dbca999504ec6c
  • glib2-doc-2.68.4-6.el9.tuxcare.els9.noarch.rpm
    sha:c931dde7c590298ae2e8690d80203c24246406de5294c87b2d4e53075b3537cc
  • glib2-static-2.68.4-6.el9.tuxcare.els9.i686.rpm
    sha:350476dad319088c296c4195b14811e4a67d867eacb3a7f3614352dd053df7fe
  • glib2-static-2.68.4-6.el9.tuxcare.els9.x86_64.rpm
    sha:038b29283234263800f3321dccdc9eb3ce24a255b01b359903cfadd089302f0e
  • glib2-tests-2.68.4-6.el9.tuxcare.els9.x86_64.rpm
    sha:4bbae04595e2f8a31fd7446e43c369733c3e954195d0b324c0215201d17c1f50
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.