Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"
Published Jun 30, 2026
8.2
HIGHCVSS 3.1
EPSS 0.85%
Description
A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.
Affected products
-
- Version 0StatusaffectedConstraints<2.88.1
- Version
-
-
-
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| GNOME | GLib | unaffected |
| ||||||
| Red Hat | Red Hat Enterprise Linux 10 | affected |
| ||||||
| Red Hat | Red Hat Enterprise Linux 6 | affected |
| ||||||
| Red Hat | Red Hat Enterprise Linux 9 | affected |
|
- < 2.88.1
- 6.0
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Cert Manager support for Red Hat OpenShift release 1.19
cert-manager/cert-manager-istio-csr-rhel9:1788348594
Fixed · RHSA-2026:63140
Cert Manager support for Red Hat OpenShift release 1.19
cert-manager/cert-manager-operator-rhel9:1788348522
Fixed · RHSA-2026:63135
Cert Manager support for Red Hat OpenShift release 1.19
cert-manager/jetstack-cert-manager-acmesolver-rhel9:1788348571
Fixed · RHSA-2026:63138
Cert Manager support for Red Hat OpenShift release 1.19
cert-manager/jetstack-cert-manager-rhel9:1788348571
Fixed · RHSA-2026:63138
Red Hat Discovery 2
discovery/discovery-server-rhel9:1788205779
Fixed · RHSA-2026:61783
Red Hat Discovery 2
discovery/discovery-ui-rhel9:1788206196
Fixed · RHSA-2026:61783
Red Hat Enterprise Linux 10
glib2-0:2.80.4-12.el10_2.21
Fixed · RHSA-2026:57015
Red Hat Enterprise Linux 10.0 Extended Update Support
glib2-0:2.80.4-4.el10_0.17
Fixed · RHSA-2026:65767
Red Hat Enterprise Linux 7 Extended Lifecycle Support
glib2-0:2.56.1-13.el7_9.1
Fixed · RHSA-2026:65773
Red Hat Enterprise Linux 8
glib2-0:2.56.4-177.el8_10
Fixed · RHSA-2026:61766
Red Hat Enterprise Linux 8
mingw-glib2-0:2.70.1-9.el8_10
Fixed · RHSA-2026:49512
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
glib2-0:2.56.4-10.el8_4.7
Fixed · RHSA-2026:65762
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
glib2-0:2.56.4-10.el8_4.7
Fixed · RHSA-2026:65762
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
glib2-0:2.56.4-158.el8_6.7
Fixed · RHSA-2026:65769
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
glib2-0:2.56.4-158.el8_6.7
Fixed · RHSA-2026:65769
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
glib2-0:2.56.4-165.el8_8.2
Fixed · RHSA-2026:65771
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
glib2-0:2.56.4-165.el8_8.2
Fixed · RHSA-2026:65771
Red Hat Enterprise Linux 9
glib2-0:2.68.4-19.el9_8.9
Fixed · RHSA-2026:55440
Red Hat Enterprise Linux 9
glib2-0:2.68.4-19.el9_8.9
Fixed · RHSA-2026:55440
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
glib2-0:2.68.4-7.el9_2.7
Fixed · RHSA-2026:65768
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
glib2-0:2.68.4-14.el9_4.8
Fixed · RHSA-2026:65770
Red Hat Enterprise Linux 9.6 Extended Update Support
glib2-0:2.68.4-16.el9_6.7
Fixed · RHSA-2026:65763
Red Hat Update Infrastructure 5
rhui5/cds-kubernetes-rhel9:1788880445
Fixed · RHSA-2026:66018
Red Hat Update Infrastructure 5
rhui5/cds-kubernetes-tp-rhel9:1787241211
Fixed · RHSA-2026:58981
Red Hat Update Infrastructure 5
rhui5/cds-rhel9:1788880464
Fixed · RHSA-2026:66018
Red Hat Update Infrastructure 5
rhui5/haproxy-rhel9:1788880456
Fixed · RHSA-2026:66018
Red Hat Update Infrastructure 5
rhui5/installer-rhel9:1788765051
Fixed · RHSA-2026:66018
Red Hat Update Infrastructure 5
rhui5/installer-tp-rhel9:1787135742
Fixed · RHSA-2026:58981
Red Hat Update Infrastructure 5
rhui5/rhua-rhel9:1788880581
Fixed · RHSA-2026:66018
Red Hat Update Infrastructure 5
rhui5/rhua-tp-rhel9:1787241260
Fixed · RHSA-2026:58981
Red Hat Enterprise Linux 10
mingw-glib2
Affected
Red Hat Enterprise Linux 6
glib2
Will not fix
Red Hat Enterprise Linux 9
mingw-glib2
Affected
Red Hat Hardened Images
glib2
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Cert Manager support for Red Hat OpenShift release 1.19 | cert-manager/cert-manager-istio-csr-rhel9:1788348594 | Fixed | RHSA-2026:63140 |
| Cert Manager support for Red Hat OpenShift release 1.19 | cert-manager/cert-manager-operator-rhel9:1788348522 | Fixed | RHSA-2026:63135 |
| Cert Manager support for Red Hat OpenShift release 1.19 | cert-manager/jetstack-cert-manager-acmesolver-rhel9:1788348571 | Fixed | RHSA-2026:63138 |
| Cert Manager support for Red Hat OpenShift release 1.19 | cert-manager/jetstack-cert-manager-rhel9:1788348571 | Fixed | RHSA-2026:63138 |
| Red Hat Discovery 2 | discovery/discovery-server-rhel9:1788205779 | Fixed | RHSA-2026:61783 |
| Red Hat Discovery 2 | discovery/discovery-ui-rhel9:1788206196 | Fixed | RHSA-2026:61783 |
| Red Hat Enterprise Linux 10 | glib2-0:2.80.4-12.el10_2.21 | Fixed | RHSA-2026:57015 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | glib2-0:2.80.4-4.el10_0.17 | Fixed | RHSA-2026:65767 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | glib2-0:2.56.1-13.el7_9.1 | Fixed | RHSA-2026:65773 |
| Red Hat Enterprise Linux 8 | glib2-0:2.56.4-177.el8_10 | Fixed | RHSA-2026:61766 |
| Red Hat Enterprise Linux 8 | mingw-glib2-0:2.70.1-9.el8_10 | Fixed | RHSA-2026:49512 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | glib2-0:2.56.4-10.el8_4.7 | Fixed | RHSA-2026:65762 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | glib2-0:2.56.4-10.el8_4.7 | Fixed | RHSA-2026:65762 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | glib2-0:2.56.4-158.el8_6.7 | Fixed | RHSA-2026:65769 |
| Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | glib2-0:2.56.4-158.el8_6.7 | Fixed | RHSA-2026:65769 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | glib2-0:2.56.4-165.el8_8.2 | Fixed | RHSA-2026:65771 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | glib2-0:2.56.4-165.el8_8.2 | Fixed | RHSA-2026:65771 |
| Red Hat Enterprise Linux 9 | glib2-0:2.68.4-19.el9_8.9 | Fixed | RHSA-2026:55440 |
| Red Hat Enterprise Linux 9 | glib2-0:2.68.4-19.el9_8.9 | Fixed | RHSA-2026:55440 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | glib2-0:2.68.4-7.el9_2.7 | Fixed | RHSA-2026:65768 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | glib2-0:2.68.4-14.el9_4.8 | Fixed | RHSA-2026:65770 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | glib2-0:2.68.4-16.el9_6.7 | Fixed | RHSA-2026:65763 |
| Red Hat Update Infrastructure 5 | rhui5/cds-kubernetes-rhel9:1788880445 | Fixed | RHSA-2026:66018 |
| Red Hat Update Infrastructure 5 | rhui5/cds-kubernetes-tp-rhel9:1787241211 | Fixed | RHSA-2026:58981 |
| Red Hat Update Infrastructure 5 | rhui5/cds-rhel9:1788880464 | Fixed | RHSA-2026:66018 |
| Red Hat Update Infrastructure 5 | rhui5/haproxy-rhel9:1788880456 | Fixed | RHSA-2026:66018 |
| Red Hat Update Infrastructure 5 | rhui5/installer-rhel9:1788765051 | Fixed | RHSA-2026:66018 |
| Red Hat Update Infrastructure 5 | rhui5/installer-tp-rhel9:1787135742 | Fixed | RHSA-2026:58981 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-rhel9:1788880581 | Fixed | RHSA-2026:66018 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-tp-rhel9:1787241260 | Fixed | RHSA-2026:58981 |
| Red Hat Enterprise Linux 10 | mingw-glib2 | Affected | n/a |
| Red Hat Enterprise Linux 6 | glib2 | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | mingw-glib2 | Affected | n/a |
| Red Hat Hardened Images | glib2 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
To mitigate this vulnerability, restrict any custom line terminator string passed to g_io_channel_set_line_term() to a maximum length of one byte before calling g_io_channel_read_line_backend(). Using the default line terminators will completely neutralize this issue.
Red Hat statement
Any applications calling g_io_channel_set_line_term() with a multi-byte line terminator (length greater than one) and subsequently calling g_io_channel_read_line_backend() are vulnerable to this issue. This flaw can cause a buffer over-read of 8 bytes, leading to an information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary. Due to these reasons, this vulnerability has been rated with a moderate severity.
Red Hat mitigation
To mitigate this vulnerability, restrict any custom line terminator string passed to g_io_channel_set_line_term() to a maximum length of one byte before calling g_io_channel_read_line_backend(). Using the default line terminators will completely neutralize this issue.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jun 30, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Jul–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.85% (0.00853) | 56.81th | v5 (v2026.06.15) |
| Jul 1, 2026 | 0.27% (0.00269) | 18.55th | v5 (v2026.06.15) |
References (54)
- https://access.redhat.com/errata/RHSA-2026:49512 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:55440 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:57015 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:58981 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:61766 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:61783 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:63135 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:63138 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:63140 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65762 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65763 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65767 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65768 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65769 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65770 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65771 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:65773 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:66018 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72394 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72395 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72399 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72470 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72475 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72476 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:72502 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:73859 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:73909 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:73929 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:73930 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:73959 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:73960 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:73961 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:73962 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74458 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74459 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74460 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74461 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74462 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74463 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74674 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74677 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74678 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74679 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74681 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74683 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74685 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74687 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74688 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74771 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-58013 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2492248 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://gitlab.gnome.org/GNOME/glib/-/issues/3925 ExploitIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-58013
- https://www.cve.org/CVERecord?id=CVE-2026-58013
Change history (0)
No recorded changes yet.