CVE-2026-58014High· 7.3▾ MidnightPoC availableA flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a deni…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 40.2 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Aug 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Exploit / PoC code exists
0.3% → 0.4%
Last analysed / modified upstream
A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.
glib < 2.88.1enterprise_linux = 6.0enterprise_linux = 7.0enterprise_linux = 8.0enterprise_linux = 9.0enterprise_linux = 10.0Upgrade past the affected range:
glib 2.88.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-58011Medium· 6.5A flaw was found in GLib
CVE-2026-58015Medium· 5.9A flaw was found in GLib
CVE-2026-58013Medium· 6.5A flaw was found in GLib
CVE-2026-58012Medium· 6.5A flaw was found in GLib
CVE-2026-58010Medium· 6.5A flaw was found in GLib
CVE-2025-4373Medium· 4.8A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function