Source: glib2.0 Version: 2.88.2-1 Severity: important Tags: security upstream Forwarded: https://gitlab.gnome.org/GNOME/glib/-/work_items/3992 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for glib2.0. CVE-2026-16118[0]: | A flaw was found in xdgmime. A heap-based buffer overflow can be | triggered in _xdg_mime_magic_parse_magic_line() in the | xdgmimemagic.c file on little-endian systems when an attacker- | controlled MIME magic file in a user-writable XDG data location | (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an | application performing MIME type detection (e.g., via | g_content_type_guess()). When performing byte-swap, incorrect | pointer arithmetic on the write side causes an out-of-bounds write | of 2 bytes, resulting in an application crash or memory corruption. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-16118 https://www.cve.org/CVERecord?id=CVE-2026-16118 [1] https://gitlab.gnome.org/GNOME/glib/-/work_items/3992 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

