Your message dated Wed, 12 Aug 2026 20:49:04 +0000
with message-id <[email protected]>
and subject line Bug#1142717: fixed in glib2.0 2.89.3-4
has caused the Debian Bug report #1142717,
regarding glib2.0: CVE-2026-16118
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1142717: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142717
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: glib2.0
Version: 2.88.2-1
Severity: important
Tags: security upstream
Forwarded: https://gitlab.gnome.org/GNOME/glib/-/work_items/3992
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for glib2.0.
CVE-2026-16118[0]:
| A flaw was found in xdgmime. A heap-based buffer overflow can be
| triggered in _xdg_mime_magic_parse_magic_line() in the
| xdgmimemagic.c file on little-endian systems when an attacker-
| controlled MIME magic file in a user-writable XDG data location
| (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an
| application performing MIME type detection (e.g., via
| g_content_type_guess()). When performing byte-swap, incorrect
| pointer arithmetic on the write side causes an out-of-bounds write
| of 2 bytes, resulting in an application crash or memory corruption.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-16118
https://www.cve.org/CVERecord?id=CVE-2026-16118
[1] https://gitlab.gnome.org/GNOME/glib/-/work_items/3992
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: glib2.0
Source-Version: 2.89.3-4
Done: Simon McVittie <[email protected]>
We believe that the bug you reported is fixed in the latest version of
glib2.0, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Simon McVittie <[email protected]> (supplier of updated glib2.0 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 12 Aug 2026 21:28:14 +0100
Source: glib2.0
Architecture: source
Version: 2.89.3-4
Distribution: experimental
Urgency: medium
Maintainer: Debian GNOME Maintainers
<[email protected]>
Changed-By: Simon McVittie <[email protected]>
Closes: 1142717
Changes:
glib2.0 (2.89.3-4) experimental; urgency=medium
.
* Merge from unstable
- d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,
d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:
Add patches from upstream (to be released in 2.89.4) to address
an out-of-bounds write if parsing a crafted XDG MIME magic file,
and fix a related test failure on minimal systems
(glib#3992 upstream, CVE-2026-16118, Closes: #1142717)
* d/p/workarounds: Mark memory-monitor-psi tests as flaky
(Mitigates: #1143197, #1143241)
Checksums-Sha1:
be33c1732a99c9dbfde2add3f590c0be5f7299d2 5075 glib2.0_2.89.3-4.dsc
fe3033fd79d181078a9fc12726d29d0b351e65b9 145252 glib2.0_2.89.3-4.debian.tar.xz
40ac9aa632a0202d5fe31a9ad3f15e901904ef50 17867576 glib2.0_2.89.3-4.git.tar.xz
03cf9e2f8f3d5a48a8a186becb6e57b3bb6ff40e 17556
glib2.0_2.89.3-4_source.buildinfo
Checksums-Sha256:
e547e77a3ded67585370610efb49326684c36f84c2baf1715c8d36282610a7ed 5075
glib2.0_2.89.3-4.dsc
01256d2c7d7d1e3f11beef4344d3d42e996c759e9a3ce38ad029f21aad61974b 145252
glib2.0_2.89.3-4.debian.tar.xz
fd6b3647be124835deec286b643a7c593ba2a697139e6c95241e287bc2ba9818 17867576
glib2.0_2.89.3-4.git.tar.xz
ac998f5eb04f41f2a4c69ac2c797938c43ec4af25b59c0a62d7d6b74003e1c8a 17556
glib2.0_2.89.3-4_source.buildinfo
Files:
70d0f5f91ca1488c214d6df2cbe5abf3 5075 libs optional glib2.0_2.89.3-4.dsc
a8c672480b890d175ecd9b0da4404584 145252 libs optional
glib2.0_2.89.3-4.debian.tar.xz
723016c4074a6aa6651a49acfe5292cc 17867576 libs None glib2.0_2.89.3-4.git.tar.xz
c7e56fda286378178c61655d02606679 17556 libs optional
glib2.0_2.89.3-4_source.buildinfo
Git-Tag-Info: tag=aded4d4c0b76d84d188d71c9622bb781642aed63
fp=7a073ad1ae694fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie <[email protected]>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmp82BsACgkQYG0ITkaD
wHmB9g/8DEC+PtGNpNOpKt5jpJqjJnPKUyKVavZnZ2fl2KwGxtSC9GZR2dMIRlwJ
cl4zXzXtqrx1fOkuK0sZg2EMKK1+D+ytfIAaP4LOb3NW7rJ7zq6b6K6WQ3Y/JJVM
ySupgAbQjgd8Fk449Zeon6lvfzymCbdMHTHpDS75ZluE7Jkbn7/yfUtsavcXbdnL
rMPKmM6Z2fL6G2Z4T0aSxCiDGKO9KL1ndPYad6MqGoL9bIni9OBXcqdkOhhtk6ji
MixEoYZ1pY6krfggzPpImbjCH7oASTCmrYegfQW4RLYxwFYvrdlThQyqRH77XXZt
BzcTReJpSHbXtXURt/OayusEZznIpMDJsZQQyX+kwJhGn0g4GrN2jIs/Sp6emK7y
WGla00PBgikdHOoGWfGvUwJkhs43zfkGJGPGM4qOJdBZl+oT5WMsD7s/HF2LWnMb
VoMiDnNLEB0hwmMPbKrXM0090F7K4VCDldplqrULUdQ0QHYpfupFe+ORfXANwFtc
KgJ15gnOcMf6OmR2G6Pyz73WDz0t61defqyHAMIxx1m4OLYz+L1VRSvlFvlQola0
2qNGUhiHwRR1F2oRc8JOltJTzahBoKHeKDYj6MLMbmEH6q+ERANPdBe4/1dggiEV
60wLGuh9sVSPYjU0pVscZNKYbrC7Y7O4HQ82aLxmRzQLmemoxe0=
=7oCK
-----END PGP SIGNATURE-----
pgpfFLcWB89Cj.pgp
Description: PGP signature
--- End Message ---