Vulnerability Description
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Glib | < 2.88.1 |
| Redhat | Enterprise Linux | 6.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2026:42063
- https://access.redhat.com/errata/RHSA-2026:42089
- https://access.redhat.com/errata/RHSA-2026:42090
- https://access.redhat.com/errata/RHSA-2026:44481
- https://access.redhat.com/errata/RHSA-2026:46836
- https://access.redhat.com/errata/RHSA-2026:49512
- https://access.redhat.com/errata/RHSA-2026:51175
- https://access.redhat.com/errata/RHSA-2026:51176
- https://access.redhat.com/errata/RHSA-2026:51177
- https://access.redhat.com/errata/RHSA-2026:51181
- https://access.redhat.com/errata/RHSA-2026:51182
- https://access.redhat.com/errata/RHSA-2026:51183
- https://access.redhat.com/errata/RHSA-2026:51184
- https://access.redhat.com/errata/RHSA-2026:51185
- https://access.redhat.com/errata/RHSA-2026:53371
FAQ
What is CVE-2026-58016?
CVE-2026-58016 is a vulnerability with a CVSS score of 7.5 (HIGH). A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `...
How severe is CVE-2026-58016?
CVE-2026-58016 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-58016?
Check the references section above for vendor advisories and patch information. Affected products include: Gnome Glib, Redhat Enterprise Linux.