PT-2026-53874 · Glib+1 · Glib+1

·

CVE-2026-58015

·

Published

2026-04-08

·

Updated

2026-09-01

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions GLib (affected versions not specified)
Description A flaw exists in the D-Bus client-side implementation of the DBUS COOKIE SHA1 SASL authentication mechanism. The system fails to validate the cookie context parameter received from the server. A malicious D-Bus server can provide a cookie context containing path traversal sequences—a technique used to access files and directories outside the intended folder—forcing the client to read arbitrary files. This allows the server to exfiltrate sensitive data by comparing guessed file contents against a generated hash. The issue involves the keyring lookup entry() and mechanism client data receive() functions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:49512
ALSA-2026:55440
ALSA-2026:57015
ALSA-2026:61766
AZL-91430
CVE-2026-58015
ECHO-0DA1-91D0-B905
JLSEC-2026-1248
OESA-2026-3109
OESA-2026-3110
OESA-2026-3111
OESA-2026-3112
OESA-2026-3113

Affected Products

Glib
Rocky Linux