Your message dated Sun, 02 Aug 2026 16:50:27 +0000
with message-id <[email protected]>
and subject line Bug#1141316: fixed in glib2.0 2.88.3-2
has caused the Debian Bug report #1141316,
regarding glib2.0: CVE-2026-58016
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1141316: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141316
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: glib2.0
X-Debbugs-CC: [email protected]
Severity: important
Tags: security
Hi,
The following vulnerability was published for glib2.0.
CVE-2026-58016[0]:
| A flaw was found in GLib. A state confusion issue exists in
| g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file
| when processing malformed D-Bus introspection XML, specifically with
| a <node> element nested within other elements like <method>,
| <signal>, <property> or <arg>. This issue can cause an unsigned
| integer overflow and lead to an out-of-bounds read, resulting in a
| denial of service.
https://gitlab.gnome.org/GNOME/glib/-/work_items/3932
https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5156 (2.89.0)
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-58016
https://www.cve.org/CVERecord?id=CVE-2026-58016
Please adjust the affected versions in the BTS as needed.
--- End Message ---
--- Begin Message ---
Source: glib2.0
Source-Version: 2.88.3-2
Done: Simon McVittie <[email protected]>
We believe that the bug you reported is fixed in the latest version of
glib2.0, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Simon McVittie <[email protected]> (supplier of updated glib2.0 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 02 Aug 2026 17:22:30 +0100
Source: glib2.0
Architecture: source
Version: 2.88.3-2
Distribution: unstable
Urgency: medium
Maintainer: Debian GNOME Maintainers
<[email protected]>
Changed-By: Simon McVittie <[email protected]>
Closes: 1141316
Changes:
glib2.0 (2.88.3-2) unstable; urgency=medium
.
* Backport patches from 2.89.0 to harden D-Bus introspection parsing
- d/p/gdbusintrospection-Add-some-assertions-before-array-deref.patch,
d/p/tests-Improve-D-Bus-introspection-test-paths.patch,
d/p/gdbusintrospection-Fix-XML-parser-state-handling-for-node.patch,
d/p/fuzzing-Add-a-fuzz-test-for-g_dbus_node_info_new_for_xml.patch:
Avoid a possible integer underflow if parsing malformed D-Bus
introspection XML sent by a malicious service
(glib#3932 upstream, CVE-2026-58016, Closes: #1141316)
* d/tests/1065022-futureproofing: Make the test pass more reliably,
by ensuring that user-session-migration gets removed rather than
making libglib2.0-0t64 be reinstalled
Checksums-Sha1:
bf8c4ac06a9768582eff50dab4f29167ef919fed 5091 glib2.0_2.88.3-2.dsc
2a94b1e955cb1d31060f7240e8a7638c4519508e 145756 glib2.0_2.88.3-2.debian.tar.xz
dff7f5b14b7cf6f15df098165b5d865ae224238c 15779444 glib2.0_2.88.3-2.git.tar.xz
40080502c431a3abaf23569f7a600bdc40973aa7 17556
glib2.0_2.88.3-2_source.buildinfo
Checksums-Sha256:
adc31bd6d4cb8684ca244c002465ea86d2a5be7f115e1ac6aeb48699f174bed6 5091
glib2.0_2.88.3-2.dsc
56cd728ff13c1d5b39ab9cf8001df330b1858054588e8490b34bff24a68b2010 145756
glib2.0_2.88.3-2.debian.tar.xz
9a25b1ee4914d57ee04f143239b23486c04df60165db9603b961583ef0ab9da4 15779444
glib2.0_2.88.3-2.git.tar.xz
5b5b7a465fba88fbce71f291c509b11b956058e95fe97ef08a80548c1002e83c 17556
glib2.0_2.88.3-2_source.buildinfo
Files:
c777505340d1585e560c7d32e80dc0ab 5091 libs optional glib2.0_2.88.3-2.dsc
491231247db8881178eff0807bf25431 145756 libs optional
glib2.0_2.88.3-2.debian.tar.xz
7cece885a14f39308f253b27d6eee951 15779444 libs None glib2.0_2.88.3-2.git.tar.xz
846a668d2b31cb74fd555617b7dffdea 17556 libs optional
glib2.0_2.88.3-2_source.buildinfo
Git-Tag-Info: tag=054c63f5a9a53068744420901b2bd3ff3a3142d8
fp=7a073ad1ae694fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie <[email protected]>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmpvcAUACgkQYG0ITkaD
wHnJ6RAAhBkvN7y95tekj8e1JQgcocvVo7NoafV0svkHeuZ78GPajJXNEcT325gH
iYM8CkLSf/RPJJyYjQWHkdqPL7ToUSXoNBMRylkilk2ys5j9v75/ppIw/BOVHOOr
5ty8uJBJFR5G+8B5GjkCBOHjzwfvpmR7Og/uopFFDGICBvsSrUksYL+aEn2LuaS9
+1QG/eSiE0xHj397rv2MruVEZYkwvH4INlySEHWDMq4BdZ9TpOEOhsb5oi7qKswD
lhmMHjhiPEAQix4BAfZx7IcZfjy85+yG7x9whix90nvwKeIbqXrIXgljnCpKiISe
jp3rRXJmwaFgGRPUey5sW5J/TvPQ6B4aMWd532qXVREI87sUMYvWXNkm2ow09u4U
evGrlaJjp57QC2BcONX0In7sN6esDTYOAMhH1rHlIhs0S+jLHiIpztUem9sV2hb+
Ucw7UONGGhcob+9JzeruQT15W3vBm4c8QhWhuSA3+ytEw1ERKZmWL7QBoNQWZFqm
3RKaJjMWWHMlIFp5q1n6Plrk0iiwClRfDLg4gTwz1GXcYrVRa36I2t67UcK4I5if
x0IbSZg79ES5V0D5+BU+vSxOw1HACpC+WKfNc40xoun4GpfFLfiOYGf5sRGUezll
98iziz4YvWGwP6+Ty0VpWDztjwuNElscz0xPw2OUXVBhxrqpj04=
=JvEb
-----END PGP SIGNATURE-----
pgp1dBW9K1Z3L.pgp
Description: PGP signature
--- End Message ---