[ALSA-2026:61766] Moderate: glib2 security update
Type:
security
Severity:
moderate
Release date:
2026-09-01
Description:
GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures. Security Fix(es): * glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() (CVE-2026-58010) * glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime (CVE-2026-58011) * glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() (CVE-2026-58012) * glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" (CVE-2026-58013) * glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" (CVE-2026-58014) * glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive (CVE-2026-58015) * GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering (CVE-2026-15588) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 glib2-tests-2.56.4-177.el8_10.aarch64.rpm 06483a60cc906f7f2f1b7506f3b29aad80162b2305254e88359e5a17bc45fe98
aarch64 glib2-devel-2.56.4-177.el8_10.aarch64.rpm 262a0f95917a5622667b6b55199ae549ea08a62ccd072faa91353c17291614ef
aarch64 glib2-static-2.56.4-177.el8_10.aarch64.rpm 98c4104376da3742a22f3f37ae16e9deb272a048d2bfca373456bd8c9d85d140
aarch64 glib2-2.56.4-177.el8_10.aarch64.rpm 9c40436fecf2645fc35cb6bd7bf651a6f782ae13f4f34446fe1340371f6613f5
aarch64 glib2-fam-2.56.4-177.el8_10.aarch64.rpm a5e7b04cccd25934a3ab64cf895c0368aff2fda66f2ecd618f9a27d43b4c1281
i686 glib2-static-2.56.4-177.el8_10.i686.rpm 034f20af5825315a55507e4f0cc75820fa809e7ba39314360db5b753d620339c
i686 glib2-2.56.4-177.el8_10.i686.rpm 13cec6b3f9a3989f4bf1df85618f8f2c5137105ec9d2fe5514ba920aa40455bd
i686 glib2-devel-2.56.4-177.el8_10.i686.rpm 173475757ce437eed10c34478f60973b64e522bca4245a9fdde262b17b74096a
noarch glib2-doc-2.56.4-177.el8_10.noarch.rpm fa282f56be76f7c20a46777827c50bfba1e3342a050bdd411dc3780913aed49f
ppc64le glib2-static-2.56.4-177.el8_10.ppc64le.rpm 1331569c888b8c42f294bbc9f184b34b8359188ed2186a25a383ec18111f21e5
ppc64le glib2-devel-2.56.4-177.el8_10.ppc64le.rpm 7f6b06378f748b2e58d178f9d6c662c9d9bcfaebfb4ac283979d751ff6418e40
ppc64le glib2-tests-2.56.4-177.el8_10.ppc64le.rpm 9573b57cf07b93b851c752148fe2badc8115f793900622a681570cd9bc6d2cf5
ppc64le glib2-fam-2.56.4-177.el8_10.ppc64le.rpm c31dc1c0ae1e95c16e504585d3c6a7b376b685f89b6b65cb0e71639a38da64a1
ppc64le glib2-2.56.4-177.el8_10.ppc64le.rpm dd2bb5d150a5c431d9aee6a1386c0ba798a1d395f8c1a46e214d4f5c4d7f41a9
s390x glib2-static-2.56.4-177.el8_10.s390x.rpm 00509a30e3489013d6aa5aea8c4a703528e166717b700a85afe2176a5d55b18e
s390x glib2-2.56.4-177.el8_10.s390x.rpm 6cd341f2ed6bc71c2e16e6d303f8cc3499024817f82fc40f4e3fdcb638dd6adc
s390x glib2-fam-2.56.4-177.el8_10.s390x.rpm 7f105b658df80c702a9f006263be66f638384f571187a05c1d91dda6b03cfbd3
s390x glib2-devel-2.56.4-177.el8_10.s390x.rpm 8c89fbf56e905649ec828fca718736568ca507ea901dbb7b7d7041c964a951d1
s390x glib2-tests-2.56.4-177.el8_10.s390x.rpm e046a6c1ebfdb06e3763dec6ab419087a5f7f41546c5d4786530e82aada4f513
x86_64 glib2-devel-2.56.4-177.el8_10.x86_64.rpm 0d94ce4d59a2b5fadfb7388b526a8daeca87317cc2e53ba3b0cebb1a49c0129e
x86_64 glib2-fam-2.56.4-177.el8_10.x86_64.rpm 4367ca7ad11f19d28dc73db2760fe842a4753c473dd24799453a6e78ad448181
x86_64 glib2-2.56.4-177.el8_10.x86_64.rpm 635709436f3ed4ee421edbda05cd3a9170e0b6112d01c7ffc90060a34040361a
x86_64 glib2-tests-2.56.4-177.el8_10.x86_64.rpm 7623e9e1301182833b6c640fa518b9d1334d941b71b387e7779a7d136f8ea5fb
x86_64 glib2-static-2.56.4-177.el8_10.x86_64.rpm b815f74c09634003f02a4dc3d64a513034aaa848118ce547618b8adfce49e034
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.