[CLSA-2026:1788000309] glib2: Fix of CVE-2026-15588
Type:
security
Severity:
Moderate
Release date:
2026-08-29 10:45:19 UTC
Description:
- CVE-2026-15588: limit the length of lines GDBusServer reads from an unauthenticated client, preventing unbounded memory and CPU consumption - add upstream prerequisite 3272.patch (gdbus: never buffer reads during server authentication), which routes all three server authentication states through the byte-at-a-time reader the CVE fix bounds
CVEs fixed:
Updated packages:
  • glib2-2.68.4-6.el9.tuxcare.els10.i686.rpm
    sha:21f5cd91639d7a40ea8b1591813c8219eca212505aa6428895c03123a4faebd1
  • glib2-2.68.4-6.el9.tuxcare.els10.x86_64.rpm
    sha:d98bdc35bf6945b3126a1f59f6fb8104dec0aa2ba39a95577e744e7e0164b091
  • glib2-devel-2.68.4-6.el9.tuxcare.els10.i686.rpm
    sha:852c5a5f837bb9b8ea7905b52fd059250a471a29b76ee55eacc334d5cd436ed6
  • glib2-devel-2.68.4-6.el9.tuxcare.els10.x86_64.rpm
    sha:13489dc889b43101ac1e60872d95b39ee27097a77416167175b0a010d8c6ddc4
  • glib2-doc-2.68.4-6.el9.tuxcare.els10.noarch.rpm
    sha:9f9d72ec6d1841f29f8d0d61ea34c8f4823039ce09f34638e425232e5e6f37b5
  • glib2-static-2.68.4-6.el9.tuxcare.els10.i686.rpm
    sha:a4b2207418e817bc28e2642139d3a0ed7523408d2a7d90743f88504758a3b68f
  • glib2-static-2.68.4-6.el9.tuxcare.els10.x86_64.rpm
    sha:a56a883da8b00f804aa4e855fd9c55aeee48ab7645503d25c8d7a26994c4833a
  • glib2-tests-2.68.4-6.el9.tuxcare.els10.x86_64.rpm
    sha:87141e334719e7835d41e515de44764f3f2f40c8c0ab63f61d4b47104eb12d42
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.