Description
A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure and Denial of Service
Action: Assess Impact
AI Analysis

Impact

The vulnerability arises from an off‑by‑one error in the gvs_tuple_is_normal function of GLib’s variant serialiser. The incorrect bounds check allows a single byte read beyond the allocated buffer during alignment padding verification. This out‑of‑bounds read can reveal one byte of memory content (minor information disclosure). If the read crosses a memory page boundary, a fault can trigger a crash, resulting in denial of service. The weakness is a classic buffer over‑read (CWE-126).

Affected Systems

Red Hat Enterprise Linux distributions 6 through 10 and the Hummingbird hardened images, as well as GNOME’s GLib package, are affected because they ship GLib bundles that contain the vulnerable code. The issue is present in GLib versions compiled for these operating systems and specifically impacts the glib/gvariant‑serialiser.c module within the package.

Risk and Exploitability

The CVSS base score of 6.5 indicates moderate severity. The EPSS score is not available, so the current exploitation probability is uncertain; nevertheless, the vulnerability is local or potentially remote depending on how the vulnerable function is exposed. As the flaw can lead to a deliberate memory disclosure and service interruption, it deserves timely mitigation. No patch or workable workaround has been released by Red Hat yet, and the vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on June 30, 2026 at 17:05 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.


OpenCVE Recommended Actions

  • Check Red Hat advisories regularly for a GLib update and apply it when released.
  • If no update is available, isolate or restrict processes that use GLib, monitor for crashes or memory disclosure, and restart affected services proactively to mitigate denial‑of‑service risk.
  • Apply any future vendor patches or security updates immediately once they are released.
  • Note that currently no workaround is available.

Generated by OpenCVE AI on June 30, 2026 at 17:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8794-1 GLib vulnerabilities
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:49512 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:55440 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:57015 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:58981 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:61766 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:61783 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:63135 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:63138 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:63140 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:65762 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:65763 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:65767 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:65768 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:65769 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:65770 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:65771 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:65773 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:66018 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:72394 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:72395 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:72399 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:72470 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:72475 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:72476 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:72502 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:73859 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:73909 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:73929 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:73930 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:73959 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:73960 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:73961 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:73962 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:74458 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:74459 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:74460 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:74461 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:74462 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:74463 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:74674 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:74677 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:74678 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:74679 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:74681 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:74683 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:74685 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:74687 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:74688 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:74771 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:75652 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:75654 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:75655 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:75657 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:75658 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:75659 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:75660 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:76042 cve-icon cve-icon
https://access.redhat.com/security/cve/CVE-2026-58010 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2492243 cve-icon cve-icon
https://gitlab.gnome.org/GNOME/glib/-/issues/3915 cve-icon cve-icon
History

Tue, 06 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
References

Mon, 05 Oct 2026 11:00:00 +0000


Fri, 02 Oct 2026 02:45:00 +0000


Thu, 01 Oct 2026 17:30:00 +0000


Wed, 30 Sep 2026 17:00:00 +0000


Wed, 30 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat ai Inference Server
CPEs cpe:/a:redhat:ai_inference_server:3.2::el9
Vendors & Products Redhat ai Inference Server
References

Tue, 29 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
References

Mon, 28 Sep 2026 14:30:00 +0000


Mon, 28 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
References

Mon, 28 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:cert_manager:1.20::el9
References

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
References

Wed, 09 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat enterprise Linux Eus
Redhat rhel Eus
Redhat rhel Tus
CPEs cpe:/a:redhat:rhel_eus:9.6::appstream
cpe:/a:redhat:rhel_eus:9.6::crb
cpe:/o:redhat:enterprise_linux_eus:10.0
cpe:/o:redhat:rhel_aus:8.6::baseos
cpe:/o:redhat:rhel_e4s:8.8::baseos
cpe:/o:redhat:rhel_eus:9.6::baseos
cpe:/o:redhat:rhel_eus_long_life:8.6::baseos
cpe:/o:redhat:rhel_tus:8.8::baseos
Vendors & Products Redhat enterprise Linux Eus
Redhat rhel Eus
Redhat rhel Tus
References

Wed, 09 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel E4s
Redhat rhel Els
CPEs cpe:/o:redhat:enterprise_linux:7 cpe:/a:redhat:rhel_e4s:9.2::appstream
cpe:/a:redhat:rhel_e4s:9.4::appstream
cpe:/o:redhat:rhel_e4s:9.2::baseos
cpe:/o:redhat:rhel_e4s:9.4::baseos
cpe:/o:redhat:rhel_els:7
Vendors & Products Redhat rhel E4s
Redhat rhel Els
References

Wed, 09 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Aus
Redhat rhel Eus Long Life
CPEs cpe:/o:redhat:rhel_aus:8.4::baseos
cpe:/o:redhat:rhel_eus_long_life:8.4::baseos
Vendors & Products Redhat rhel Aus
Redhat rhel Eus Long Life
References

Tue, 08 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat cert Manager
CPEs cpe:/a:redhat:cert_manager:1.19::el9
Vendors & Products Redhat cert Manager
References

Tue, 01 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat discovery
CPEs cpe:/a:redhat:discovery:2::el9
Vendors & Products Redhat discovery
References

Mon, 31 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:8::baseos
References

Tue, 25 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhui
CPEs cpe:/a:redhat:rhui:5::el9
Vendors & Products Redhat rhui
References

Wed, 19 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:10.2
References

Mon, 17 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:9::appstream
cpe:/a:redhat:enterprise_linux:9::crb
cpe:/o:redhat:enterprise_linux:9::baseos
References

Mon, 03 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:8::crb
References

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Gnome
Gnome glib
Redhat hardened Images
Vendors & Products Gnome
Gnome glib
Redhat hardened Images

Tue, 30 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 13:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.
Title Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()
First Time appeared Redhat
Redhat enterprise Linux
Redhat hummingbird
Weaknesses CWE-126
CPEs cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat hummingbird
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}


Subscriptions

Gnome Glib
Redhat Ai Inference Server Cert Manager Discovery Enterprise Linux Enterprise Linux Eus Hardened Images Hummingbird Openshift Ai Rhel Aus Rhel E4s Rhel Els Rhel Eus Rhel Eus Long Life Rhel Tus Rhui
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-06T02:08:57.552Z

Reserved: 2026-06-26T20:59:47.855Z

Link: CVE-2026-58010

cve-icon Vulnrichment

Updated: 2026-06-30T14:03:42.815Z

cve-icon NVD

Status : Modified

Published: 2026-06-30T13:19:17.067

Modified: 2026-10-06T03:17:06.590

Link: CVE-2026-58010

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T10:01:41Z

Weaknesses