CVE-2026-58016
ADVISORY - debianSummary
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a element nested within other elements like , , or . This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.
- glib2.0 (bug https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141316) [trixie] - glib2.0 (Minor issue) [bookworm] - glib2.0 (Minor issue; GDBus introspection-XML OOB-read DoS; no upstream fix yet) [bullseye] - glib2.0 (Minor issue; GDBus introspection-XML OOB-read DoS; no upstream fix yet) https://gitlab.gnome.org/GNOME/glib/-/work_items/3932 https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5156 (2.89.0)
EPSS Score: 0.00421 (0.344)
Common Weakness Enumeration (CWE)
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in