CVE-2026-58012
ADVISORY - debianSummary
A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the G_REGEX_RAW compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.
- glib2.0 2.88.1-2 [trixie] - glib2.0 (Minor issue) [bookworm] - glib2.0 (Minor issue; g_regex_replace raw-mode over-read, needs G_REGEX_RAW) [bullseye] - glib2.0 (Minor issue; g_regex_replace raw-mode over-read, needs G_REGEX_RAW) https://gitlab.gnome.org/GNOME/glib/-/work_items/3918 https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5132 (2.89.0) https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5134 (2.88.1) https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5135 (2.86.5)
EPSS Score: 0.00322 (0.245)
Common Weakness Enumeration (CWE)
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in