Release date:
2026-07-16 12:08:07 UTC
Description:
* SECURITY UPDATE: One-byte heap under-read in GKeyFile locale string list
- debian/patches/CVE-2026-58014.patch: guard len > 0 before reading
value[len - 1] when a key has an empty value in
g_key_file_get_locale_string_list() in glib/gkeyfile.c
- CVE-2026-58014
* SECURITY UPDATE: Path traversal via unvalidated D-Bus cookie context
- debian/patches/CVE-2026-58015.patch: validate the server-supplied
cookie_context (reject path-traversal characters) and harden cookie_id
validation in the DBUS_COOKIE_SHA1 client authentication mechanism in
gio/gdbusauthmechanismsha1.c
- CVE-2026-58015
Updated packages:
-
libglib2.0-0_2.58.3-2+deb10u6+tuxcare.els5_amd64.deb
sha:8051c20d6b17c6d82dcf03a2bb67cef5d7956894
-
libglib2.0-bin_2.58.3-2+deb10u6+tuxcare.els5_amd64.deb
sha:19a339d7c16baa361e7f444106728794765b06d2
-
libglib2.0-data_2.58.3-2+deb10u6+tuxcare.els5_all.deb
sha:2eb39ed281ffb620804ac03837c25e5cf58f94fd
-
libglib2.0-dev_2.58.3-2+deb10u6+tuxcare.els5_amd64.deb
sha:8b1021d3999ea419bc9bbf60fb9be22d679c5380
-
libglib2.0-dev-bin_2.58.3-2+deb10u6+tuxcare.els5_amd64.deb
sha:d81a3a96cbedca5cdb69fe56efa71d2d1151c828
-
libglib2.0-doc_2.58.3-2+deb10u6+tuxcare.els5_all.deb
sha:3d2ba524598ef47ec6c429826eb2bd1b835bf9d8
-
libglib2.0-tests_2.58.3-2+deb10u6+tuxcare.els5_amd64.deb
sha:3434ce59e5f7938ecea9edaca22745d4d15cdc50
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.