- What: Red Hat released a security update for glib2
- Impact: Addresses potential security issues in the library
Red Hat Product Errata RHSA-2026:65762 - Security Advisory Issued: 2026-09-09 Updated: 2026-09-09 RHSA-2026:65762 - Security Advisory Overview Updated Packages Synopsis Moderate: glib2 security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for glib2 is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures. Security Fix(es): glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() (CVE-2026-58010) glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime (CVE-2026-58011) glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() (CVE-2026-58012) glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" (CVE-2026-58013) glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" (CVE-2026-58014) glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive (CVE-2026-58015) GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering (CVE-2026-15588) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 Fixes BZ - 2492243 - CVE-2026-58010 glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() BZ - 2492245 - CVE-2026-58011 glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime BZ - 2492247 - CVE-2026-58012 glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() BZ - 2492248 - CVE-2026-58013 glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" BZ - 2492255 - CVE-2026-58014 glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" BZ - 2492256 - CVE-2026-58015 glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive BZ - 2499675 - CVE-2026-15588 GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering CVEs CVE-2026-15588 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58015 References https://access.redhat.com/security/updates/classification/#moderate Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 SRPM glib2-2.56.4-10.el8_4.7.src.rpm SHA-256: b8d1175bb05687415774404aa83deac760b89a1583ac02e308eb39fca2dd297d x86_64 glib2-2.56.4-10.el8_4.7.i686.rpm SHA-256: f6e88ae67e23e819262a043a907909b1b17ccbcdbfc197689a3d00fbaeaebbe6 glib2-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: 64b788028d9fd41b11b89fea08f48657f6e5c2b7e0201bcf707b78657fe34380 glib2-debuginfo-2.56.4-10.el8_4.7.i686.rpm SHA-256: e83437b753be0ccb77a7952d1fb3e399d5047c8b0d9c40fc185780246ca5f662 glib2-debuginfo-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: 39bdcabf7d5054c5c98fcd53335f11a6fc95e79e8a2ff888c3c75057a8ed2a66 glib2-debugsource-2.56.4-10.el8_4.7.i686.rpm SHA-256: ba4b5ef6c7145f48b97d0a544f17131778f8d3ae593f51aa433f2fba74b43761 glib2-debugsource-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: b2a2ef43fffc9705dcc6f2c4d0b095bdf113fd5b4afc4a3578579bdff35180ce glib2-devel-2.56.4-10.el8_4.7.i686.rpm SHA-256: 10cad548172b7f21978aa2ac927c0889eacbcd63863d4c123f1254eb4f953594 glib2-devel-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: 0f79341c50b83e35429ed4e59f096689c92868031f526f7238d23c7dd0978717 glib2-devel-debuginfo-2.56.4-10.el8_4.7.i686.rpm SHA-256: 5f3e5fa6652fade3b059529f73fd47454ffa03d88ee19cc2aab23121f27f6ed2 glib2-devel-debuginfo-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: 04c48832665b15a5b30711f659ca62a7b01085ff2a99ca07cca68f846b8371fb glib2-fam-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: 30fde262c054781e29ed93f18640a19ef2085a27c9776ca8e4e88583d3b2e9da glib2-fam-debuginfo-2.56.4-10.el8_4.7.i686.rpm SHA-256: 6c3599c8cbb6e15977aed02a13ffbc9fd1ec7765ed703f01d741b805e01808dc glib2-fam-debuginfo-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: 0942cbd979a34437ae19d98c231ef0d0e7a20c03a7c811ed20f9ff8c5c5000d6 glib2-tests-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: c5ad0dfc3c63936483deace386c15a49b49e0c15d9ae25ad71204267741dc289 glib2-tests-debuginfo-2.56.4-10.el8_4.7.i686.rpm SHA-256: 1c7f303c06764b6fac87c49a9eb63089f75227a83d664858015726c0691b7a9a glib2-tests-debuginfo-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: fb1b813bbbfe106718ef3a40312946f7c3d188492c6f3e223dc1eaa6979d00ba Red Hat Enterprise Linux Server - AUS 8.4 SRPM glib2-2.56.4-10.el8_4.7.src.rpm SHA-256: b8d1175bb05687415774404aa83deac760b89a1583ac02e308eb39fca2dd297d x86_64 glib2-2.56.4-10.el8_4.7.i686.rpm SHA-256: f6e88ae67e23e819262a043a907909b1b17ccbcdbfc197689a3d00fbaeaebbe6 glib2-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: 64b788028d9fd41b11b89fea08f48657f6e5c2b7e0201bcf707b78657fe34380 glib2-debuginfo-2.56.4-10.el8_4.7.i686.rpm SHA-256: e83437b753be0ccb77a7952d1fb3e399d5047c8b0d9c40fc185780246ca5f662 glib2-debuginfo-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: 39bdcabf7d5054c5c98fcd53335f11a6fc95e79e8a2ff888c3c75057a8ed2a66 glib2-debugsource-2.56.4-10.el8_4.7.i686.rpm SHA-256: ba4b5ef6c7145f48b97d0a544f17131778f8d3ae593f51aa433f2fba74b43761 glib2-debugsource-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: b2a2ef43fffc9705dcc6f2c4d0b095bdf113fd5b4afc4a3578579bdff35180ce glib2-devel-2.56.4-10.el8_4.7.i686.rpm SHA-256: 10cad548172b7f21978aa2ac927c0889eacbcd63863d4c123f1254eb4f953594 glib2-devel-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: 0f79341c50b83e35429ed4e59f096689c92868031f526f7238d23c7dd0978717 glib2-devel-debuginfo-2.56.4-10.el8_4.7.i686.rpm SHA-256: 5f3e5fa6652fade3b059529f73fd47454ffa03d88ee19cc2aab23121f27f6ed2 glib2-devel-debuginfo-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: 04c48832665b15a5b30711f659ca62a7b01085ff2a99ca07cca68f846b8371fb glib2-fam-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: 30fde262c054781e29ed93f18640a19ef2085a27c9776ca8e4e88583d3b2e9da glib2-fam-debuginfo-2.56.4-10.el8_4.7.i686.rpm SHA-256: 6c3599c8cbb6e15977aed02a13ffbc9fd1ec7765ed703f01d741b805e01808dc glib2-fam-debuginfo-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: 0942cbd979a34437ae19d98c231ef0d0e7a20c03a7c811ed20f9ff8c5c5000d6 glib2-tests-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: c5ad0dfc3c63936483deace386c15a49b49e0c15d9ae25ad71204267741dc289 glib2-tests-debuginfo-2.56.4-10.el8_4.7.i686.rpm SHA-256: 1c7f303c06764b6fac87c49a9eb63089f75227a83d664858015726c0691b7a9a glib2-tests-debuginfo-2.56.4-10.el8_4.7.x86_64.rpm SHA-256: fb1b813bbbfe106718ef3a40312946f7c3d188492c6f3e223dc1eaa6979d00ba The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .