Buffer Underflow Vulnerability in Glib Parsing Logic
CVE-2026-1485
2.8LOW
What is CVE-2026-1485?
A vulnerability in Glib's content type parsing logic allows for buffer underflow due to improper handling of header line lengths as signed integers. This leads to integer wraparound when processing large inputs, resulting in pointer underflow and potentially out-of-bounds memory access. To exploit this vulnerability, a local user must process a specially crafted treemagic file, which could result in a local denial of service and compromise application stability.
References
CVSS V3.1
Score:
2.8
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank treeplus for reporting this issue.