CVE-2026-58010
ADVISORY - debianSummary
A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.
- glib2.0 2.88.1-2 [trixie] - glib2.0 (Minor issue) [bookworm] - glib2.0 (Minor issue; GVariant deserialiser 1-byte over-read, reachability-gated) [bullseye] - glib2.0 (Minor issue; GVariant deserialiser 1-byte over-read, reachability-gated) https://gitlab.gnome.org/GNOME/glib/-/work_items/3915 https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5129 (2.89.0) https://gitlab.gnome.org/GNOME/glib/-/commit/8338414f6560216efe67d3cbf549e32f8630252a (2.89.0) https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5134 (2.88.1) https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5135 (2.86.5)
EPSS Score: 0.00322 (0.246)
Common Weakness Enumeration (CWE)
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in