USN-8794-1: GLib vulnerabilities
What it means
GLib, una libreria C utilizzata in Ubuntu, presenta diversi problemi di sicurezza, tra cui buffer overflow, errori di gestione della memoria e vulnerabilità nell'autenticazione D-Bus. Questi possono portare a denial of service, esposizione di informazioni sensibili e accesso non autorizzato. Le patch sono disponibili per correggere le vulnerabilità.
Why it matters
Per le PMI italiane, queste vulnerabilità possono compromettere la stabilità e la sicurezza dei sistemi operativi, esponendo dati sensibili e causando interruzioni del servizio. La mancanza di patch potrebbe portare a attacchi mirati e danni economici.
Recommended actions
- Applicare le patch disponibili per GLib (libglib2.0-0, libglib2.0-bin)
- Verificare l'aggiornamento di tutti i sistemi Ubuntu e componenti dipendenti da GLib
- Configurare firewall per limitare l'accesso a servizi D-Bus
- Monitorare i log di sistema per segnalare attività sospette
- Implementare controlli di input rigorosi per prevenire buffer overflow
- Utilizzare Ubuntu Pro per ottenere supporto di sicurezza aggiuntivo
Potential operational benefits
- Riduzione della superficie esposta alle vulnerabilità
- Miglioramento della stabilità e della sicurezza del sistema
- Prevenzione di accessi non autorizzati e danni al sistema
Translation in progress
The official content is available in the original language. The Italian version will be published once automated checks are complete.
Text acquired from the source
It was discovered that GLib's GDBus authentication mechanism failed to enforce length limitations on data lines read from a client. An unauthenticated attacker could exploit this to cause a denial of service via resource exhaustion. (CVE-2026-15588) It was discovered that the xdgmime library in GLib had a heap-based buffer overflow. An attacker-controlled MIME magic file could cause an out-of-bounds write on little-endian systems. (CVE-2026-16118) It was discovered that GLib had an off-by-one error in the GVariant serialiser. An attacker could use this to cause an out-of-bounds read, leading to information disclosure or a denial of service. (CVE-2026-58010) It was discovered that GLib had an out-of-bounds read in GDateTime. An attacker could use this to corrupt date output and cause a denial of service. (CVE-2026-58011) It was discovered that GLib's g_regex_replace() function had a buffer over-read when used with the G_REGEX_RAW flag. An attacker could use this to cause information disclosure or a denial of service. (CVE-2026-58012) It was discovered that GLib's GIOChannel had a buffer over-read when using a custom line terminator. An attacker could use this to cause information disclosure or a denial of service. (CVE-2026-58013) It was discovered that GLib's GKeyFile had an off-by-one error when loading a key file with an empty value. An attacker could use this to cause an out-of-bounds access or a denial of service. (CVE-2026-58014) It was discovered that GLib's DBUS_COOKIE_SHA1 authentication mechanism failed to validate the cookie_context parameter. A malicious D-Bus server could use this to read arbitrary files from the client. (CVE-2026-58015) It was discovered that GLib's D-Bus introspection XML parser had a state confusion issue. An attacker could use this to ca
- Source
- Ubuntu Security Notices
- Publishing entity
- Ubuntu Security
- Entity type
- vendor security
- Area
- Global
- Original language
- en · translation in preparation
- Publication
- 21/09/2026 18:25
- MITRE ATT&CK
- T1486, T1078, T1190
- CVE
- CVE-2026-15588, CVE-2026-16118, CVE-2026-58010, CVE-2026-58011, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015
Affected products and versions
The collector will check NVD and the available official vendor advisories.