VDB

CVE-2026-58015

CVE-2026-58015 PUBLISHED CVSS 5.9 MEDIUM

Reported by redhat · Published June 30, 2026

A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.

Risk Scores

CVSS 3.1
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
GNOMEGLib0
Red HatRed Hat Enterprise Linux 100:2.80.4-12.el10_2.21
Red HatRed Hat Enterprise Linux 80:2.70.1-9.el8_10
Red HatRed Hat Enterprise Linux 80:2.56.4-177.el8_10
Red HatRed Hat Enterprise Linux 90:2.68.4-19.el9_8.9
Red HatRed Hat Enterprise Linux 90:2.68.4-19.el9_8.9
Red HatRed Hat Discovery 21788205779
Red HatRed Hat Discovery 21788206196
Red HatRed Hat Update Infrastructure 51787241211
Red HatRed Hat Update Infrastructure 51787135742
Red HatRed Hat Update Infrastructure 51787241260
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Hardened Images
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Update Infrastructure 51787241260, 1787241260, 1787241260
Red HatRed Hat Enterprise Linux 80:2.56.4-177.el8_10, 0:2.56.4-177.el8_10

…and 13 more

Timeline

  • Jun 30, 2026 CVE Published
  • Jul 1, 2026 Coalition ESS Score
  • Jul 2, 2026 EPSS Score
  • Aug 3, 2026 Distribution Patch
  • Aug 3, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 17, 2026 Distribution Patch
  • Aug 17, 2026 Security Advisory
  • Aug 17, 2026 Distribution Patch
  • Aug 19, 2026 Distribution Patch
  • Aug 19, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›