VDB
CVE-2026-58015
CVE-2026-58015
PUBLISHED
CVSS 5.9 MEDIUM
Reported by redhat · Published June 30, 2026
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
Risk Scores
CVSS 3.1
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| GNOME | GLib | 0 |
| Red Hat | Red Hat Enterprise Linux 10 | 0:2.80.4-12.el10_2.21 |
| Red Hat | Red Hat Enterprise Linux 8 | 0:2.70.1-9.el8_10 |
| Red Hat | Red Hat Enterprise Linux 8 | 0:2.56.4-177.el8_10 |
| Red Hat | Red Hat Enterprise Linux 9 | 0:2.68.4-19.el9_8.9 |
| Red Hat | Red Hat Enterprise Linux 9 | 0:2.68.4-19.el9_8.9 |
| Red Hat | Red Hat Discovery 2 | 1788205779 |
| Red Hat | Red Hat Discovery 2 | 1788206196 |
| Red Hat | Red Hat Update Infrastructure 5 | 1787241211 |
| Red Hat | Red Hat Update Infrastructure 5 | 1787135742 |
| Red Hat | Red Hat Update Infrastructure 5 | 1787241260 |
| Red Hat | Red Hat Enterprise Linux 10 | |
| Red Hat | Red Hat Enterprise Linux 6 | |
| Red Hat | Red Hat Enterprise Linux 7 | |
| Red Hat | Red Hat Enterprise Linux 9 | |
| Red Hat | Red Hat Hardened Images | |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat Enterprise Linux 10 | |
| Red Hat | Red Hat Update Infrastructure 5 | 1787241260, 1787241260, 1787241260 |
| Red Hat | Red Hat Enterprise Linux 8 | 0:2.56.4-177.el8_10, 0:2.56.4-177.el8_10 |
…and 13 more
Timeline
- Jun 30, 2026 CVE Published
- Jul 1, 2026 Coalition ESS Score
- Jul 2, 2026 EPSS Score
- Aug 3, 2026 Distribution Patch
- Aug 3, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 17, 2026 Distribution Patch
- Aug 17, 2026 Security Advisory
- Aug 17, 2026 Distribution Patch
- Aug 19, 2026 Distribution Patch
- Aug 19, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
References
- RHSA-2026:49512 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:55440 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:57015 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:58981 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:61766 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:61783 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2492256 issue-trackingx_refsource_REDHAT