Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.5%top 56%

CVE-2026-58016: Integer Underflow (Wrap or Wraparound) in GNOME GLib

0
High
Published: 07/20/2026 (07/20/2026, 16:55:22 UTC)
Source: GCVE Database
Vendor/Project: GNOME
Product: GLib

Description

A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

redhat/glib2
pkg:rpm/redhat/glib2
Affected versions
=8<8.10

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/06/2026, 22:38:06 UTC

Technical Analysis

CVE-2026-58016 is an integer underflow vulnerability in the glib2 library, specifically in the gio/gdbusintrospection.c source file, triggered through the g_dbus_node_info_new_for_xml function. This vulnerability affects Red Hat Enterprise Linux versions 9 and 10, including various architectures and extended update support versions. Red Hat has issued security advisories RHSA-2026:42089 and RHSA-2026:42063 providing updated glib2 packages that fix this issue. The vulnerability is rated as having an important security impact by Red Hat and is associated with CWE-191 (Integer Underflow).

Potential Impact

The integer underflow vulnerability could potentially lead to unexpected behavior or security issues in applications relying on the glib2 library's D-Bus introspection functionality. Red Hat rates the security impact as important (high severity). There are no reports of active exploitation in the wild at this time.

Mitigation Recommendations

Red Hat has released patched versions of the glib2 package for affected Red Hat Enterprise Linux 9 and 10 versions. Users should apply the official updates as described in Red Hat advisories RHSA-2026:42089 and RHSA-2026:42063. Detailed instructions for applying these updates are available at https://access.redhat.com/articles/11258. Applying these updates will remediate the integer underflow vulnerability. No additional mitigation steps are indicated by the vendor.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:42090
Cve Count
1
Additional Cves
[]
Cvss Version
null

Threat ID: 6a5e79ed2a4a8d59899bbb39

Added to database: 07/20/2026, 19:41:33 UTC

Last enriched: 08/06/2026, 22:38:06 UTC

Last updated: 09/03/2026, 22:52:13 UTC

Views: 121

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses