Your message dated Sat, 01 Aug 2026 00:20:12 +0000
with message-id <[email protected]>
and subject line Bug#1142835: fixed in glib2.0 2.88.3-1
has caused the Debian Bug report #1142835,
regarding glib2.0: CVE-2026-15588
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1142835: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142835
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: glib2.0
Version: 2.88.2-1
Severity: important
Tags: security upstream
Forwarded: https://gitlab.gnome.org/GNOME/glib/-/issues/3985
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for glib2.0.

CVE-2026-15588[0]:
| A denial-of-service and resource exhaustion vulnerability exists
| within the `GDBus` component of GLib. The `gdbusauth` authentication
| mechanism fails to enforce proper length limitations on data lines
| read from a client. An unauthenticated local or remote attacker can
| exploit this lack of input validation by sending excessively long
| streams of data, causing the application to consume massive amounts
| of system memory and CPU, potentially leading to a crash or system
| hang.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-15588
    https://www.cve.org/CVERecord?id=CVE-2026-15588
[1] https://gitlab.gnome.org/GNOME/glib/-/issues/3985
[2] 
https://gitlab.gnome.org/GNOME/glib/-/commit/4235f7b42ba51d6fdb4abd7c4276031802f39834

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: glib2.0
Source-Version: 2.88.3-1
Done: Simon McVittie <[email protected]>

We believe that the bug you reported is fixed in the latest version of
glib2.0, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon McVittie <[email protected]> (supplier of updated glib2.0 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 31 Jul 2026 21:13:54 +0100
Source: glib2.0
Architecture: source
Version: 2.88.3-1
Distribution: unstable
Urgency: medium
Maintainer: Debian GNOME Maintainers 
<[email protected]>
Changed-By: Simon McVittie <[email protected]>
Closes: 1142835
Changes:
 glib2.0 (2.88.3-1) unstable; urgency=medium
 .
   * New upstream stable release
     - Fixes resource exhaustion if a malicious client can contact a
       GDBusServer (CVE-2026-15588, Closes: #1142835)
   * d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:
     Add patch from upstream to fix autopkgtest regression
   * d/control, d/gbp.conf: Use debian/forky branch
Checksums-Sha1:
 1a3b46a526764b86c09f3288e97daee9d10130b1 4939 glib2.0_2.88.3-1.dsc
 f844ba1b1075bec1f80d3069e3f9437dfc86b42d 666552 
glib2.0_2.88.3.orig-unicode-data.tar.xz
 1831d83abab126895df34fe04cf3e86dee5d8c44 5794356 glib2.0_2.88.3.orig.tar.xz
 e12e44f1782d6566e982909e5521fd56871628cf 143208 glib2.0_2.88.3-1.debian.tar.xz
 4a9f2fa4368cd832a1399f5d5b49702a786f8f26 7243 glib2.0_2.88.3-1_source.buildinfo
Checksums-Sha256:
 6a1bb48796e67c2366582514874f08a8704a442bfc0f66dcb54be6580400a7ce 4939 
glib2.0_2.88.3-1.dsc
 4b55352323696c72187f855981ed1f7d1594a53f257f7803a928749cab9f9f44 666552 
glib2.0_2.88.3.orig-unicode-data.tar.xz
 ab24d24e698dfa1e408b7bcdb508f4aafc906185a8b8ce72fdf79bbbdc9b383b 5794356 
glib2.0_2.88.3.orig.tar.xz
 5238a5b569b3d30ddee47191a90da68e409ee084814f6eb9b3938351ec1020b7 143208 
glib2.0_2.88.3-1.debian.tar.xz
 e89651592c1a656e0425889097c229488555b4e222f2fffbe4a431074c3c3629 7243 
glib2.0_2.88.3-1_source.buildinfo
Files:
 501c6587dcaf624a7f47a151a10a81e7 4939 libs optional glib2.0_2.88.3-1.dsc
 4e5631558a56f2ddc14b8f431aef3b12 666552 libs optional 
glib2.0_2.88.3.orig-unicode-data.tar.xz
 b61c04cfbf55b0d24fbe64e4ac9e9d56 5794356 libs optional 
glib2.0_2.88.3.orig.tar.xz
 c69c8b3a057d6b191e50a105d6ea95cb 143208 libs optional 
glib2.0_2.88.3-1.debian.tar.xz
 fbeb95cae38b99a8b98e1ef8bf0ebe64 7243 libs optional 
glib2.0_2.88.3-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEegc60a5pT6Jb/2LlI1wJnT6zMHYFAmptMbcACgkQI1wJnT6z
MHZW3w/+OOt0K8TgsAodlH+/lgEc7hj39zTXq5JTaoUqhNNm2wJcgow3/ZDK9hAq
BwmTLQpAv5zyi9Vzy83duJV2assYZav8bcJXLPRhHPnkIK3tQSBX6ft//9YhBgf/
+s6njCwsRZQq9vCMxkYexA0A2lx0m5m0+B5721iTx+vxtcajL8zzLDO0rc56sTTN
NhkowSXgo2OwQ3CEqvJxMoQXirqV82EKodoFG7Fagmr++4PaDe+wMNHi6WJmRNzv
Xs2HmZnjviA2RJWHQ/XmVcUgPCZxIJvCoYJsyH/Yt8GpU7UHyrUluwmVNzYpI1ON
cn9muxnlBvoWy5bCH92VzqCF+y3Yep37NH8W40fe4MiDgF1rjgqe3DgNS1tHU8BS
vhxN68bFpI3oKyTYS8CuEB8TDxj/tuO8IADPRNrRTXEcV5jXvBcjtmjPA4pvP7mH
Myk1ijDXFNLQMBUPrsdksN7eyeigk4mXB2aa8Oo+m4HI7JxZKbRiwq6kfSUhLzdv
Mix5p0gcG7H6VfV9oJUovHLMVdKiIkCt8HWx2rTMffk8+FJyP7CDdaqmM/HHVKoL
mClB5H3LsrPt4CgvIYwuxjsdrIl/eJMFUaRXXPwdnSvD1/C/BAgdggY7gceBK3jr
iR//bP+x9pYR3S9bPfr6rUzqeRXvQqgbSv/IOmRUd8HHvYyTQ6g=
=83ZE
-----END PGP SIGNATURE-----

Attachment: pgpMyO_R92BeX.pgp
Description: PGP signature


--- End Message ---

Reply via email to