A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade mingw64-glib2Upgrade mingw32-glib2-staticUpgrade mingw32-glib2Upgrade mingw64-glib2-static | Aug 4, 2026 | Aug 3, 2026 |
| Amazon_linux_2023 | — | Upgrade glib2-debuginfoUpgrade glib2-debugsourceUpgrade glib2-devel-debuginfoUpgrade glib2-staticUpgrade glib2Upgrade glib2-testsUpgrade glib2-develUpgrade glib2-docUpgrade glib2-tests-debuginfo | Jul 21, 2026 | Jun 30, 2026 |
| Debian | — | Upgrade glib2.0 | Sep 21, 2026 | Jun 30, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Sep 16, 2026 | Apr 8, 2026 |
| Redhat_linux | — | Upgrade glib2-testsUpgrade mingw64-glib2Upgrade mingw32-glib2-debuginfoUpgrade mingw64-glib2-debuginfoUpgrade glib2-tests-debuginfoNo solution existsUpgrade glib2-fam-debuginfoUpgrade glib2-debugsourceUpgrade glib2-develUpgrade glib2-devel-debuginfoUpgrade glib2-famUpgrade glib2-docUpgrade glib2-staticUpgrade glib2Upgrade mingw32-glib2Upgrade glib2-debuginfoUpgrade mingw32-glib2-staticUpgrade mingw64-glib2-static | Jul 17, 2026 | Apr 8, 2026 |
| Rocky_linux | — | Upgrade glib2-testsUpgrade glib2-tests-debuginfoUpgrade glib2-staticUpgrade glib2-debugsourceUpgrade glib2-devel-debuginfoUpgrade glib2-fam-debuginfoUpgrade glib2-debuginfoUpgrade glib2-develUpgrade glib2Upgrade glib2-fam | Aug 20, 2026 | Aug 17, 2026 |
| Ubuntu | — | Upgrade libglib2.0-binUpgrade libglib2.0-0t64Upgrade libglib2.0-0Upgrade libglib2.0-bin (Ubuntu Pro)Upgrade libglib2.0-0 (Ubuntu Pro) | Sep 22, 2026 | Sep 21, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 2, 2026 | Jun 30, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub