PT-2026-53873 · Gnome+1 · Mingw-Glib2+2
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
glib2 (affected versions not specified)
mingw-glib2 (affected versions not specified)
Description
An off-by-one error exists in the
g key file get locale string list() function within the gkeyfile.c file. This issue occurs when the software loads a key file containing an empty value, leading to a 1-byte out-of-bounds read. An attacker can trigger this by providing a crafted .ini-style key file for the application to parse. If the out-of-bounds access crosses a page boundary, it can cause the process to crash, resulting in a denial of service.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rocky Linux
Glib2
Mingw-Glib2