EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

USN-8794-1: GLib vulnerabilities

Official source
EudorIA operational summary

What it means

Priority 70/100

GLib, una libreria C utilizzata in Ubuntu, presenta diversi problemi di sicurezza, tra cui buffer overflow, errori di gestione della memoria e vulnerabilità nell'autenticazione D-Bus. Questi possono portare a denial of service, esposizione di informazioni sensibili e accesso non autorizzato. Le patch sono disponibili per correggere le vulnerabilità.

Why it matters

Per le PMI italiane, queste vulnerabilità possono compromettere la stabilità e la sicurezza dei sistemi operativi, esponendo dati sensibili e causando interruzioni del servizio. La mancanza di patch potrebbe portare a attacchi mirati e danni economici.

Potential operational benefits

  • Riduzione della superficie esposta alle vulnerabilità
  • Miglioramento della stabilità e della sicurezza del sistema
  • Prevenzione di accessi non autorizzati e danni al sistema
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementFirewall NGFW / IPSMonitoraggio / SIEMSegmentazione di reteBackup & DR
AudienceITSOCCISO
Information centre

Translation in progress

Ubuntu Security

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

It was discovered that GLib's GDBus authentication mechanism failed to enforce length limitations on data lines read from a client. An unauthenticated attacker could exploit this to cause a denial of service via resource exhaustion. (CVE-2026-15588) It was discovered that the xdgmime library in GLib had a heap-based buffer overflow. An attacker-controlled MIME magic file could cause an out-of-bounds write on little-endian systems. (CVE-2026-16118) It was discovered that GLib had an off-by-one error in the GVariant serialiser. An attacker could use this to cause an out-of-bounds read, leading to information disclosure or a denial of service. (CVE-2026-58010) It was discovered that GLib had an out-of-bounds read in GDateTime. An attacker could use this to corrupt date output and cause a denial of service. (CVE-2026-58011) It was discovered that GLib's g_regex_replace() function had a buffer over-read when used with the G_REGEX_RAW flag. An attacker could use this to cause information disclosure or a denial of service. (CVE-2026-58012) It was discovered that GLib's GIOChannel had a buffer over-read when using a custom line terminator. An attacker could use this to cause information disclosure or a denial of service. (CVE-2026-58013) It was discovered that GLib's GKeyFile had an off-by-one error when loading a key file with an empty value. An attacker could use this to cause an out-of-bounds access or a denial of service. (CVE-2026-58014) It was discovered that GLib's DBUS_COOKIE_SHA1 authentication mechanism failed to validate the cookie_context parameter. A malicious D-Bus server could use this to read arbitrary files from the client. (CVE-2026-58015) It was discovered that GLib's D-Bus introspection XML parser had a state confusion issue. An attacker could use this to ca

Source
Ubuntu Security Notices
Publishing entity
Ubuntu Security
Entity type
vendor security
Area
Global
Original language
en · translation in preparation
Publication
21/09/2026 18:25
MITRE ATT&CK
T1486, T1078, T1190
CVE
CVE-2026-15588, CVE-2026-16118, CVE-2026-58010, CVE-2026-58011, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source