A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.
CVSS Details
- CVSS 3.1 Base Score: 2.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade glib2.0 | Feb 24, 2026 | Feb 24, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jan 27, 2026 |
| Suse | — | Upgrade glib2-devel-32bitUpgrade glib2-tools-32bitUpgrade glib2-langUpgrade glib2-tests-develUpgrade libgobject-2_0-0Upgrade libgirepository-2_0-0Upgrade libgthread-2_0-0-32bitUpgrade glib2-docUpgrade libgmodule-2_0-0Upgrade libgio-2_0-0Upgrade typelib-1_0-GIRepository-3_0Upgrade typelib-1_0-GObject-2_0Upgrade gio-branding-upstreamUpgrade libglib-2_0-0Upgrade libgio-2_0-0-32bitUpgrade typelib-1_0-Gio-2_0Upgrade typelib-1_0-GLibUnix-2_0Upgrade typelib-1_0-GModule-2_0Upgrade glib2-develUpgrade typelib-1_0-GLib-2_0Upgrade libglib-2_0-0-32bitUpgrade libgmodule-2_0-0-32bitUpgrade glib2-toolsUpgrade glib2-devel-staticUpgrade libgthread-2_0-0Upgrade libgobject-2_0-0-32bit | Feb 4, 2026 | Jan 31, 2026 |
| Ubuntu | — | Upgrade libglib2.0-0Upgrade libglib2.0-binUpgrade libglib2.0-0t64 | Feb 6, 2026 | Jan 27, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Jan 27, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub