Source: glib2.0 Version: 2.88.2-1 Severity: important Tags: security upstream Forwarded: https://gitlab.gnome.org/GNOME/glib/-/issues/3985 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for glib2.0. CVE-2026-15588[0]: | A denial-of-service and resource exhaustion vulnerability exists | within the `GDBus` component of GLib. The `gdbusauth` authentication | mechanism fails to enforce proper length limitations on data lines | read from a client. An unauthenticated local or remote attacker can | exploit this lack of input validation by sending excessively long | streams of data, causing the application to consume massive amounts | of system memory and CPU, potentially leading to a crash or system | hang. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-15588 https://www.cve.org/CVERecord?id=CVE-2026-15588 [1] https://gitlab.gnome.org/GNOME/glib/-/issues/3985 [2] https://gitlab.gnome.org/GNOME/glib/-/commit/4235f7b42ba51d6fdb4abd7c4276031802f39834 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

