VDB

CVE-2026-58010

CVE-2026-58010 PUBLISHED CVSS 6.5 MEDIUM

Reported by redhat · Published June 30, 2026

A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Affected Products

VendorProductVersions
GNOMEGLib0, 0
Red HatRed Hat Enterprise Linux 100:2.80.4-12.el10_2.21
Red HatRed Hat Enterprise Linux 80:2.70.1-9.el8_10
Red HatRed Hat Enterprise Linux 80:2.56.4-177.el8_10
Red HatRed Hat Enterprise Linux 90:2.68.4-19.el9_8.9
Red HatRed Hat Enterprise Linux 90:2.68.4-19.el9_8.9
Red HatRed Hat Discovery 21788205779
Red HatRed Hat Discovery 21788206196
Red HatRed Hat Update Infrastructure 51787241211
Red HatRed Hat Update Infrastructure 51787135742
Red HatRed Hat Update Infrastructure 51787241260
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Hardened Images
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Discovery 21788206196
Red HatRed Hat Hardened Images
Red HatRed Hat Enterprise Linux 10

…and 11 more

Timeline

  • Jun 30, 2026 CVE Published
  • Jul 1, 2026 Coalition ESS Score
  • Jul 2, 2026 EPSS Score
  • Aug 3, 2026 Distribution Patch
  • Aug 3, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 17, 2026 Distribution Patch
  • Aug 17, 2026 Security Advisory
  • Aug 17, 2026 Distribution Patch
  • Aug 19, 2026 Distribution Patch
  • Aug 19, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›