[CLSA-2026:1784203659] Fix CVE(s): CVE-2026-58014, CVE-2026-58015, CVE-2026-58016
Type:
security
Severity:
Critical
Release date:
2026-07-16 12:08:07 UTC
Description:
* SECURITY UPDATE: One-byte heap under-read in GKeyFile locale string list - debian/patches/CVE-2026-58014.patch: guard len > 0 before reading value[len - 1] when a key has an empty value in g_key_file_get_locale_string_list() in glib/gkeyfile.c - CVE-2026-58014 * SECURITY UPDATE: Path traversal via unvalidated D-Bus cookie context - debian/patches/CVE-2026-58015.patch: validate the server-supplied cookie_context (reject path-traversal characters) and harden cookie_id validation in the DBUS_COOKIE_SHA1 client authentication mechanism in gio/gdbusauthmechanismsha1.c - CVE-2026-58015
Updated packages:
  • libglib2.0-0_2.58.3-2+deb10u6+tuxcare.els5_amd64.deb
    sha:8051c20d6b17c6d82dcf03a2bb67cef5d7956894
  • libglib2.0-bin_2.58.3-2+deb10u6+tuxcare.els5_amd64.deb
    sha:19a339d7c16baa361e7f444106728794765b06d2
  • libglib2.0-data_2.58.3-2+deb10u6+tuxcare.els5_all.deb
    sha:2eb39ed281ffb620804ac03837c25e5cf58f94fd
  • libglib2.0-dev_2.58.3-2+deb10u6+tuxcare.els5_amd64.deb
    sha:8b1021d3999ea419bc9bbf60fb9be22d679c5380
  • libglib2.0-dev-bin_2.58.3-2+deb10u6+tuxcare.els5_amd64.deb
    sha:d81a3a96cbedca5cdb69fe56efa71d2d1151c828
  • libglib2.0-doc_2.58.3-2+deb10u6+tuxcare.els5_all.deb
    sha:3d2ba524598ef47ec6c429826eb2bd1b835bf9d8
  • libglib2.0-tests_2.58.3-2+deb10u6+tuxcare.els5_amd64.deb
    sha:3434ce59e5f7938ecea9edaca22745d4d15cdc50
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.