[ALSA-2026:49512] Important: mingw-glib2 security update
Type:
security
Severity:
important
Release date:
2026-08-03
Description:
GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures. Security Fix(es): * glib: GLib: Buffer underflow in GVariant parser leads to heap corruption (CVE-2025-14087) * glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() (CVE-2026-58010) * glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime (CVE-2026-58011) * glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() (CVE-2026-58012) * glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" (CVE-2026-58013) * glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" (CVE-2026-58014) * glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive (CVE-2026-58015) * glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" (CVE-2026-58016) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
noarch mingw64-glib2-static-2.70.1-9.el8_10.noarch.rpm 1326bc1c5b14c11c870d3011b13ed7da6b177412404c85aeef6815454174b36f
noarch mingw32-glib2-2.70.1-9.el8_10.noarch.rpm b8b7ae6a165301957fa063fbd0807a55cfafb4021cc8f71d7b16b937c832ed91
noarch mingw32-glib2-static-2.70.1-9.el8_10.noarch.rpm d2cd96cb052c09e5069ef47154b42b5c277de55effa4a5f361e3e247050c7fce
noarch mingw64-glib2-2.70.1-9.el8_10.noarch.rpm ece1e27260093e72198fb221cd4c48026b68b3d2987ee53723bcbb103c95b41a
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.