PT-2026-53873 · Gnome+1 · Mingw-Glib2+2

·

CVE-2026-58014

·

Published

2026-04-07

·

Updated

2026-09-01

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions glib2 (affected versions not specified) mingw-glib2 (affected versions not specified)
Description An off-by-one error exists in the g key file get locale string list() function within the gkeyfile.c file. This issue occurs when the software loads a key file containing an empty value, leading to a 1-byte out-of-bounds read. An attacker can trigger this by providing a crafted .ini-style key file for the application to parse. If the out-of-bounds access crosses a page boundary, it can cause the process to crash, resulting in a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:49512
ALSA-2026:55440
ALSA-2026:57015
ALSA-2026:61766
AZL-91445
CVE-2026-58014
ECHO-CD39-6531-4266
JLSEC-2026-1247
OESA-2026-3109
OESA-2026-3110
OESA-2026-3111
OESA-2026-3112
OESA-2026-3113
OPENSUSE-SU-2026:21410-1
SUSE-SU-2026:22846-1
SUSE-SU-2026:22928-1
SUSE-SU-2026:23009-1
SUSE-SU-2026:23078-1
SUSE-SU-2026:3235-1
SUSE-SU-2026:3236-1
SUSE-SU-2026:3341-1

Affected Products

Rocky Linux
Glib2
Mingw-Glib2