CVE-2026-58016High· 7.5▾ TwilightA flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other ele…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
0.5% → 0.5%
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a node element nested within other elements like method, signal, property or arg. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.
glib < 2.88.1enterprise_linux = 6.0enterprise_linux = 7.0enterprise_linux = 8.0enterprise_linux = 9.0enterprise_linux = 10.0Upgrade past the affected range:
glib 2.88.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-58015Medium· 5.9A flaw was found in GLib
CVE-2026-58014High· 7.3A flaw was found in GLib
CVE-2026-58013Medium· 6.5A flaw was found in GLib
CVE-2026-58012Medium· 6.5A flaw was found in GLib
CVE-2026-58011Medium· 6.5A flaw was found in GLib
CVE-2026-58010Medium· 6.5A flaw was found in GLib