A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.
CVSS Details
- CVSS 3.1 Base Score: 8.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade mingw32-glib2Upgrade mingw64-glib2Upgrade mingw64-glib2-staticUpgrade mingw32-glib2-static | Aug 4, 2026 | Aug 3, 2026 |
| Amazon_linux_2023 | — | Upgrade glib2-testsUpgrade glib2-develUpgrade glib2-tests-debuginfoUpgrade glib2-debuginfoUpgrade glib2-debugsourceUpgrade glib2Upgrade glib2-staticUpgrade glib2-docUpgrade glib2-devel-debuginfo | Jul 21, 2026 | Jun 30, 2026 |
| Debian | — | Upgrade glib2.0 | Sep 21, 2026 | Jun 30, 2026 |
| Redhat_linux | — | Upgrade mingw32-glib2-staticUpgrade glib2-famUpgrade glib2-fam-debuginfoUpgrade mingw32-glib2Upgrade glib2-debugsourceUpgrade glib2-docUpgrade mingw64-glib2-debuginfoUpgrade glib2-tests-debuginfoUpgrade glib2-devel-debuginfoUpgrade glib2-staticUpgrade glib2-develUpgrade mingw64-glib2Upgrade mingw32-glib2-debuginfoUpgrade glib2-testsUpgrade glib2No solution existsUpgrade mingw64-glib2-staticUpgrade glib2-debuginfo | Jul 17, 2026 | Mar 26, 2026 |
| Rocky_linux | — | Upgrade glib2-devel-debuginfoUpgrade glib2Upgrade glib2-tests-debuginfoUpgrade glib2-debugsourceUpgrade glib2-staticUpgrade glib2-develUpgrade glib2-famUpgrade glib2-debuginfoUpgrade glib2-testsUpgrade glib2-fam-debuginfo | Aug 20, 2026 | Aug 17, 2026 |
| Ubuntu | — | Upgrade libglib2.0-0t64Upgrade libglib2.0-binUpgrade libglib2.0-bin (Ubuntu Pro)Upgrade libglib2.0-0Upgrade libglib2.0-0 (Ubuntu Pro) | Sep 22, 2026 | Sep 21, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 2, 2026 | Jun 30, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub