Your message dated Fri, 21 Aug 2026 15:14:28 +0000
with message-id <[email protected]>
and subject line Bug#1142835: fixed in glib2.0 2.89.3-5
has caused the Debian Bug report #1142835,
regarding glib2.0: CVE-2026-15588
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1142835: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142835
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: glib2.0
Version: 2.88.2-1
Severity: important
Tags: security upstream
Forwarded: https://gitlab.gnome.org/GNOME/glib/-/issues/3985
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for glib2.0.
CVE-2026-15588[0]:
| A denial-of-service and resource exhaustion vulnerability exists
| within the `GDBus` component of GLib. The `gdbusauth` authentication
| mechanism fails to enforce proper length limitations on data lines
| read from a client. An unauthenticated local or remote attacker can
| exploit this lack of input validation by sending excessively long
| streams of data, causing the application to consume massive amounts
| of system memory and CPU, potentially leading to a crash or system
| hang.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-15588
https://www.cve.org/CVERecord?id=CVE-2026-15588
[1] https://gitlab.gnome.org/GNOME/glib/-/issues/3985
[2]
https://gitlab.gnome.org/GNOME/glib/-/commit/4235f7b42ba51d6fdb4abd7c4276031802f39834
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: glib2.0
Source-Version: 2.89.3-5
Done: Jeremy Bícha <[email protected]>
We believe that the bug you reported is fixed in the latest version of
glib2.0, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Jeremy Bícha <[email protected]> (supplier of updated glib2.0 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 21 Aug 2026 16:37:11 +0200
Source: glib2.0
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 2.89.3-5
Distribution: unstable
Urgency: medium
Maintainer: Debian GNOME Maintainers
<[email protected]>
Changed-By: Jeremy Bícha <[email protected]>
Closes: 1141316 1142717 1142835
Changes:
glib2.0 (2.89.3-5) unstable; urgency=medium
.
* Release to unstable
.
glib2.0 (2.89.3-4) experimental; urgency=medium
.
* Merge from unstable
- d/p/xdgmime-Check-if-caches-are-set-before-dumping-them.patch,
d/p/Fix-CVE-2026-16118-heap-buffer-overflow-in-xdgmimemagic.c.patch:
Add patches from upstream (to be released in 2.89.4) to address
an out-of-bounds write if parsing a crafted XDG MIME magic file,
and fix a related test failure on minimal systems
(glib#3992 upstream, CVE-2026-16118, Closes: #1142717)
* d/p/workarounds: Mark memory-monitor-psi tests as flaky
(Mitigates: #1143197, #1143241)
.
glib2.0 (2.89.3-3) experimental; urgency=medium
.
[ Simon McVittie ]
* Merge packaging from unstable
- d/tests/1065022-futureproofing: Make the test pass more reliably,
by ensuring that user-session-migration gets removed rather than
making libglib2.0-0t64 be reinstalled
* Drop patches added by 2.88.3-2, already part of 2.89.x
.
glib2.0 (2.89.3-2) experimental; urgency=medium
.
* d/p/gio-tests-services-Fix-installed-service-file-containing-.patch:
Add patch from upstream to fix autopkgtest regression
* d/changelog: Mention CVE-2026-15588, CVE-2026-58016 in the appropriate
previous changelog entry
.
glib2.0 (2.89.3-1) experimental; urgency=medium
.
* New upstream release
* debian/libglib2.0-0t64.symbols: Add new symbols
.
glib2.0 (2.89.2-1) experimental; urgency=medium
.
* New upstream release
- Fixes possible integer underflow when parsing D-Bus introspection XML
(CVE-2026-58016, Closes: #1141316)
- Fixes resource exhaustion if a malicious client can contact a GDBusServer
(CVE-2026-15588, Closes: #1142835)
* d/p: Refresh patches
* d/libglib2.0-0t64.symbols: Add new symbol
Checksums-Sha1:
92f5c3d181b04bdf2bd126fd09f1c7d47d33d99b 4809 glib2.0_2.89.3-5.dsc
af3872a6ab841fbd4618d11dcda02317a2fea995 145180 glib2.0_2.89.3-5.debian.tar.xz
c14291048b10042d3ac029149f7e2baff3e6fac3 11637
glib2.0_2.89.3-5_source.buildinfo
Checksums-Sha256:
d051d1b8f572ce65c8959d97d6433c2c685c6374fbf52a71d11fbadfe210e701 4809
glib2.0_2.89.3-5.dsc
0fe2c3c9bf1a90376edb6ec3e4e602190b9df72c987cf3f3961e0a132d4aa5fb 145180
glib2.0_2.89.3-5.debian.tar.xz
f57785267e300de810197e17b7dea6a05c60ee2aa8aa39ef041c0ea105c8208b 11637
glib2.0_2.89.3-5_source.buildinfo
Files:
51909061d0431c875d197b9aa150a732 4809 libs optional glib2.0_2.89.3-5.dsc
f7eb67b8b062f653390d1b9ca48502f8 145180 libs optional
glib2.0_2.89.3-5.debian.tar.xz
1677d300f3671162f2584bca30d78f2f 11637 libs optional
glib2.0_2.89.3-5_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmqIYuYACgkQ5mx3Wuv+
bH1LlBAA0sAu2oTrdbp5reAEPTYrtgzuEM3RZvfZZ9PFjyXnlrBOalJ9O7Oz3Al3
47bIKAyAPsqt18QXthdpdSsBmQ4awj5Lo4rlS4P2tFHkZ3tnTQKTcTlHGGdm26d2
DUw6CV9hmcT/ipoVRey/yTUdYO/1u0lrqpRJ4B5qJu6HBJ3lnqp2Uj6f7FINEd5R
YMbKvhmierGBkSg84fmBHZluK8iSMZwdU7p/u9DZ2Wvp2CG5kyb2q2aWL/pwXrL1
XjKLQsFf9U7rOdtcT0ZusL8sfey6+u+v91wIyXUZ2xXsUru4RKbgRhXFfJQbGy7p
sxHKGNmRlggpj5RrWJvoREqPkkj79RzwQbkzr6CaiDIjaLriaAfXVyCkc7+N5JdG
HlVNUH3atAu5/Byi3tbai0ugZPiE/mzFe+1iM04vpvtY6e7tXGx12dKDna9nSeGI
G7wHhHZ1MyZRgNr54oemzxdXGb9Ez2bLdbR+1XPiQ/VK6ITSSMxWjCWPjwaFBUJT
SmPhiw9lCzetSFUfiDT0npX64ekOBBuNuqO3cZzvjc/ZJtW2VbNX1/EgNGfeSKZt
NhsmDpSgcYN1/tzAG5ln2ID12U9j2/pKx67Xs7IBrypWhotsGiKOQ0K3/6MAxuVS
35tdNnm64rNfW4+VEWbUnxRmLhGtYdfYgSzN0lRj3TT59S++hYM=
=Hr3H
-----END PGP SIGNATURE-----
pgprkGCZNIJJh.pgp
Description: PGP signature
--- End Message ---