A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the G_REGEX_RAW compile flag and case-change… (CVE-2026-58012)
A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.
AI Analysis
Technical Summary
CVE-2026-58012 is a buffer over-read vulnerability in GLib's g_regex_replace function. When the function is used with the G_REGEX_RAW compile flag and case-change replacement escapes, the string_append function processes matched substrings using UTF-8 functions that expect valid UTF-8 input, but the input is treated as raw bytes. This mismatch can cause reading beyond the intended buffer, potentially disclosing a small amount of memory (1-5 bytes) and causing denial of service if the over-read crosses a page boundary. The issue is fixed in GLib version 2.70.1.
Potential Impact
The vulnerability can cause minor information disclosure of 1-5 bytes and denial of service due to buffer over-read. There is no indication of code execution or privilege escalation. No known exploits in the wild have been reported.
Mitigation Recommendations
An official fix is available in GLib version 2.70.1. Users should update to version 2.70.1 or later to remediate this vulnerability. Refer to the Red Hat advisory RHSA-2026:49512 for update instructions. No additional mitigation steps are indicated by the vendor.
A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the G_REGEX_RAW compile flag and case-change… (CVE-2026-58012)
Description
A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.
CVSS v3.1
Score 6.5medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-58012 is a buffer over-read vulnerability in GLib's g_regex_replace function. When the function is used with the G_REGEX_RAW compile flag and case-change replacement escapes, the string_append function processes matched substrings using UTF-8 functions that expect valid UTF-8 input, but the input is treated as raw bytes. This mismatch can cause reading beyond the intended buffer, potentially disclosing a small amount of memory (1-5 bytes) and causing denial of service if the over-read crosses a page boundary. The issue is fixed in GLib version 2.70.1.
Potential Impact
The vulnerability can cause minor information disclosure of 1-5 bytes and denial of service due to buffer over-read. There is no indication of code execution or privilege escalation. No known exploits in the wild have been reported.
Mitigation Recommendations
An official fix is available in GLib version 2.70.1. Users should update to version 2.70.1 or later to remediate this vulnerability. Refer to the Red Hat advisory RHSA-2026:49512 for update instructions. No additional mitigation steps are indicated by the vendor.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-vwg8-37h9-g38g
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-58012"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Patch Information
Threat ID: 6a83335dbf8831d5392a655d
Added to database: 08/17/2026, 16:14:21 UTC
Last enriched: 09/29/2026, 05:06:48 UTC
Last updated: 10/03/2026, 02:46:05 UTC
Views: 52
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.