USN-8794-1: GLib vulnerabilities
Cosa significa
GLib, una libreria C utilizzata in Ubuntu, presenta diversi problemi di sicurezza, tra cui buffer overflow, errori di gestione della memoria e vulnerabilità nell'autenticazione D-Bus. Questi possono portare a denial of service, esposizione di informazioni sensibili e accesso non autorizzato. Le patch sono disponibili per correggere le vulnerabilità.
Perché conta
Per le PMI italiane, queste vulnerabilità possono compromettere la stabilità e la sicurezza dei sistemi operativi, esponendo dati sensibili e causando interruzioni del servizio. La mancanza di patch potrebbe portare a attacchi mirati e danni economici.
Azioni consigliate
- Applicare le patch disponibili per GLib (libglib2.0-0, libglib2.0-bin)
- Verificare l'aggiornamento di tutti i sistemi Ubuntu e componenti dipendenti da GLib
- Configurare firewall per limitare l'accesso a servizi D-Bus
- Monitorare i log di sistema per segnalare attività sospette
- Implementare controlli di input rigorosi per prevenire buffer overflow
- Utilizzare Ubuntu Pro per ottenere supporto di sicurezza aggiuntivo
Benefici operativi potenziali
- Riduzione della superficie esposta alle vulnerabilità
- Miglioramento della stabilità e della sicurezza del sistema
- Prevenzione di accessi non autorizzati e danni al sistema
Traduzione in elaborazione
Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.
Testo acquisito dalla fonte
It was discovered that GLib's GDBus authentication mechanism failed to enforce length limitations on data lines read from a client. An unauthenticated attacker could exploit this to cause a denial of service via resource exhaustion. (CVE-2026-15588) It was discovered that the xdgmime library in GLib had a heap-based buffer overflow. An attacker-controlled MIME magic file could cause an out-of-bounds write on little-endian systems. (CVE-2026-16118) It was discovered that GLib had an off-by-one error in the GVariant serialiser. An attacker could use this to cause an out-of-bounds read, leading to information disclosure or a denial of service. (CVE-2026-58010) It was discovered that GLib had an out-of-bounds read in GDateTime. An attacker could use this to corrupt date output and cause a denial of service. (CVE-2026-58011) It was discovered that GLib's g_regex_replace() function had a buffer over-read when used with the G_REGEX_RAW flag. An attacker could use this to cause information disclosure or a denial of service. (CVE-2026-58012) It was discovered that GLib's GIOChannel had a buffer over-read when using a custom line terminator. An attacker could use this to cause information disclosure or a denial of service. (CVE-2026-58013) It was discovered that GLib's GKeyFile had an off-by-one error when loading a key file with an empty value. An attacker could use this to cause an out-of-bounds access or a denial of service. (CVE-2026-58014) It was discovered that GLib's DBUS_COOKIE_SHA1 authentication mechanism failed to validate the cookie_context parameter. A malicious D-Bus server could use this to read arbitrary files from the client. (CVE-2026-58015) It was discovered that GLib's D-Bus introspection XML parser had a state confusion issue. An attacker could use this to ca
- Fonte
- Ubuntu Security Notices
- Entità pubblicatrice
- Ubuntu Security
- Tipo entità
- vendor security
- Area
- Global
- Lingua originale
- en · traduzione in preparazione
- Pubblicazione
- 21/09/2026 18:25
- MITRE ATT&CK
- T1486, T1078, T1190
- CVE
- CVE-2026-15588, CVE-2026-16118, CVE-2026-58010, CVE-2026-58011, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015
Prodotti e versioni interessati
Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.