PT-2026-53874 · Glib+1 · Glib+1
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GLib (affected versions not specified)
Description
A flaw exists in the D-Bus client-side implementation of the DBUS COOKIE SHA1 SASL authentication mechanism. The system fails to validate the
cookie context parameter received from the server. A malicious D-Bus server can provide a cookie context containing path traversal sequences—a technique used to access files and directories outside the intended folder—forcing the client to read arbitrary files. This allows the server to exfiltrate sensitive data by comparing guessed file contents against a generated hash. The issue involves the keyring lookup entry() and mechanism client data receive() functions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Glib
Rocky Linux