Description
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.
Published: 2026-06-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in GLib’s GIO library introduces a state‑confusion issue in g_dbus_node_info_new_for_xml() when it parses malformed D‑Bus introspection XML, specifically when a <node> element is nested within elements like <method>, <signal>, <property> or <arg>. This can trigger an unsigned integer overflow and lead to an out‑of‑bounds read, which may crash the application, resulting in a denial of service. The weakness is identified as a type conversion error (CWE‑191).

Affected Systems

The vulnerability affects systems that ship GLib with the GIO library, notably Red Hat Enterprise Linux distributions from version 6 through 10 and Red Hat Hardened Images. Any software on these platforms that processes D‑Bus introspection XML is potentially exposed.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, and the EPSS score of < 1% indicates a very low likelihood of exploitation. The CWE indicates that the flaw resides in handling of data. Based on the description, it is inferred that an attacker who can supply malformed D‑Bus introspection XML—either locally or remotely—to an application using g_dbus_node_info_new_for_xml() could trigger the overflow and crash it. No additional privileges or external infrastructure are required beyond the ability to deliver the crafted XML. The vulnerability is not listed in CISA's KEV catalog.

Generated by OpenCVE AI on August 4, 2026 at 08:14 UTC.

Remediation

Vendor Workaround

To mitigate this vulnerability, implement input validation to sanitize untrusted D-Bus introspection XML, specifically rejecting malformed structures such as <node> elements improperly nested within <method>, <signal>, <property> or <arg> elements before calling g_dbus_node_info_new_for_xml(). Alternatively, restricting the application to only process XML input from trusted, authenticated sources will completely neutralize this issue.


OpenCVE Recommended Actions

  • Implement input validation to reject malformed D‑Bus introspection XML, rejecting <node> elements nested inside <method>, <signal>, <property>, or <arg> before calling g_dbus_node_info_new_for_xml().
  • Restrict the processing of D‑Bus introspection XML to sources that are trusted and authenticated, thereby preventing untrusted inputs from reaching the vulnerable function.
  • When available, upgrade GLib to a future release that includes a fix, and keep the system updated to avoid similar data‑handling issues.

Generated by OpenCVE AI on August 4, 2026 at 08:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat enterprise Linux Eus
Redhat rhel Els
Redhat rhel Eus
CPEs cpe:/o:redhat:enterprise_linux:7 cpe:/a:redhat:rhel_eus:9.6::appstream
cpe:/a:redhat:rhel_eus:9.6::crb
cpe:/o:redhat:enterprise_linux_eus:10.0
cpe:/o:redhat:rhel_els:7
cpe:/o:redhat:rhel_eus:9.6::baseos
Vendors & Products Redhat enterprise Linux Eus
Redhat rhel Els
Redhat rhel Eus
References

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Eus Long Life
Redhat rhel Tus
CPEs cpe:/a:redhat:rhel_e4s:9.2::appstream
cpe:/a:redhat:rhel_e4s:9.4::appstream
cpe:/o:redhat:rhel_aus:8.4::baseos
cpe:/o:redhat:rhel_aus:8.6::baseos
cpe:/o:redhat:rhel_e4s:8.8::baseos
cpe:/o:redhat:rhel_e4s:9.2::baseos
cpe:/o:redhat:rhel_e4s:9.4::baseos
cpe:/o:redhat:rhel_eus_long_life:8.4::baseos
cpe:/o:redhat:rhel_eus_long_life:8.6::baseos
cpe:/o:redhat:rhel_tus:8.8::baseos
Vendors & Products Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Eus Long Life
Redhat rhel Tus
References

Mon, 03 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:8
References

Tue, 28 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> or <arg>. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service. A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.

Mon, 27 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat discovery
CPEs cpe:/a:redhat:discovery:2::el9
Vendors & Products Redhat discovery
References

Thu, 23 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhui
CPEs cpe:/a:redhat:rhui:5::el9
Vendors & Products Redhat rhui
References

Tue, 21 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:9::appstream
cpe:/a:redhat:enterprise_linux:9::crb
cpe:/o:redhat:enterprise_linux:9::baseos
References

Mon, 20 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:10.2
References

Mon, 20 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:8::crb
cpe:/o:redhat:enterprise_linux:8::baseos
References

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Gnome
Gnome glib
Redhat hardened Images
Vendors & Products Gnome
Gnome glib
Redhat hardened Images

Tue, 30 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 13:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a <node> element nested within other elements like <method>, <signal>, <property> or <arg>. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.
Title Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
First Time appeared Redhat
Redhat enterprise Linux
Redhat hummingbird
Weaknesses CWE-191
CPEs cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat hummingbird
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Gnome Glib
Redhat Discovery Enterprise Linux Enterprise Linux Eus Hardened Images Hummingbird Rhel Aus Rhel E4s Rhel Els Rhel Eus Rhel Eus Long Life Rhel Tus Rhui
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-07T01:57:08.287Z

Reserved: 2026-06-26T20:59:47.856Z

Link: CVE-2026-58016

cve-icon Vulnrichment

Updated: 2026-06-30T13:58:11.595Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T08:15:06Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)