Your message dated Wed, 12 Aug 2026 09:36:01 +0000
with message-id <[email protected]>
and subject line Bug#1142717: fixed in glib2.0 2.88.3-3
has caused the Debian Bug report #1142717,
regarding glib2.0: CVE-2026-16118
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1142717: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142717
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: glib2.0
Version: 2.88.2-1
Severity: important
Tags: security upstream
Forwarded: https://gitlab.gnome.org/GNOME/glib/-/work_items/3992
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for glib2.0.

CVE-2026-16118[0]:
| A flaw was found in xdgmime. A heap-based buffer overflow can be
| triggered in _xdg_mime_magic_parse_magic_line() in the
| xdgmimemagic.c file on little-endian systems when an attacker-
| controlled MIME magic file in a user-writable XDG data location
| (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an
| application performing MIME type detection (e.g., via
| g_content_type_guess()). When performing byte-swap, incorrect
| pointer arithmetic on the write side causes an out-of-bounds write
| of 2 bytes, resulting in an application crash or memory corruption.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-16118
    https://www.cve.org/CVERecord?id=CVE-2026-16118
[1] https://gitlab.gnome.org/GNOME/glib/-/work_items/3992

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: glib2.0
Source-Version: 2.88.3-3
Done: Simon McVittie <[email protected]>

We believe that the bug you reported is fixed in the latest version of
glib2.0, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon McVittie <[email protected]> (supplier of updated glib2.0 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 12 Aug 2026 10:10:25 +0100
Source: glib2.0
Architecture: source
Version: 2.88.3-3
Distribution: unstable
Urgency: medium
Maintainer: Debian GNOME Maintainers 
<[email protected]>
Changed-By: Simon McVittie <[email protected]>
Closes: 1142717
Changes:
 glib2.0 (2.88.3-3) unstable; urgency=medium
 .
   * d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,
     d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:
     Add patches from upstream (to be released in 2.89.4) to address
     an out-of-bounds write if parsing a crafted XDG MIME magic file,
     and fix a related test failure on minimal systems
     (glib#3992 upstream, CVE-2026-16118, Closes: #1142717)
Checksums-Sha1:
 060a88b44df733ee92680f9c106d1f9a599f8b8d 5091 glib2.0_2.88.3-3.dsc
 4dfd103c4aca09d825a83b736e8d57fc7cc5a080 146728 glib2.0_2.88.3-3.debian.tar.xz
 cc1b678ad5c92135315fc3153bdb190bda22e887 15783988 glib2.0_2.88.3-3.git.tar.xz
 661a1e16f75301d5ceec1602a4b1255016e5b862 17556 
glib2.0_2.88.3-3_source.buildinfo
Checksums-Sha256:
 36848fbcc2718313c03b34150cec8ab921ffa3790d14d16bf5906b364c5a3798 5091 
glib2.0_2.88.3-3.dsc
 8109e35ac5fd6cfc72c913357b667a584bcdb8f20efa119337db407139f34bb7 146728 
glib2.0_2.88.3-3.debian.tar.xz
 ada1e7b3c50596f80355a191c30f866762cb5d9417f487e4576b6bb17387f05c 15783988 
glib2.0_2.88.3-3.git.tar.xz
 e471ebe2691e20e582f7b25c0a06fe4e396f132e5086636d78811976e909029d 17556 
glib2.0_2.88.3-3_source.buildinfo
Files:
 09ef239c61ccff5d7b78e83c12328984 5091 libs optional glib2.0_2.88.3-3.dsc
 16db7c7cb1714a7e9be8c3d37b826630 146728 libs optional 
glib2.0_2.88.3-3.debian.tar.xz
 1592d1cb6e8da540059699d8e5192eda 15783988 libs None glib2.0_2.88.3-3.git.tar.xz
 8e9215742f85d5a2e0655d04ccc52813 17556 libs optional 
glib2.0_2.88.3-3_source.buildinfo
Git-Tag-Info: tag=46316932734b6f0fc0346a69bc8908a9ca4e7d30 
fp=7a073ad1ae694fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie <[email protected]>

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmp8ORoACgkQYG0ITkaD
wHkr0g/+L0nOAYoTXNJgDrgSHMC5cN4jCSIyn8hFB3TxwwWy2AFzzwZpvBwSkqbD
vk3bMBfz/DJszyp0GCO+dtX1RVTNIc5FO4kpLsBdVVBo41kWG56ID2fJSJGra+tt
2USkORUTFUmGCzJWiV2/9JowGWySgdaMXBjSBYwTvl+QN9xkzV+eXzTO17MMCaH4
XOVEfhCMHMiezFY23vIjl/9J+IT98INLJh4YtYNJsvub5tqoYa55UcCgkLYejkFP
MgASBeA8yDs9YaztxLtibXqhTvmEIaFil1D1L4W2j786wL0VUHN6Kieb4hKohLV2
HvBga+zEfRJoXypIpdxTkNZRGRqSRaE9zwekjxfbLU4QQBFNV3qOUECpSgwJCv4w
JgWsUXhD1EEGbSJGYDQi/Wdnx1hcvnmESScjnBCDxPjz6WzW3rzzOAAa7yidCVNS
WX5t5MfPgNxdX3PCvBO14nePJ7jjCYD4YXvwif8x1oO6otbzaHAp29fXQ5fW2EZn
QrbMZni76rrGjtX+IUAR9zswYvKz8ygqF1CMMVcDqjoNJoQkgKFHAT+clzXjymPy
vJvPged4H+b6pzoTIM7mNWX08fMpMyRUEcRWLGPXW81M4LVnFF3xkQUPhPJlazl4
XcbcTCD7GWzUdhDx2FC2wsfkReBGAHTelPSXKN5NmhrlRuNuZDU=
=jGDe
-----END PGP SIGNATURE-----

Attachment: pgpUg1avGdnoP.pgp
Description: PGP signature


--- End Message ---

Reply via email to