Denial-of-Service Vulnerability in GLib's GDBus by GNOME
CVE-2026-15588
5.3MEDIUM
What is CVE-2026-15588?
A denial-of-service and resource exhaustion issue has been identified in the GDBus component of GLib, due to the gdbusauth authentication mechanism failing to enforce length constraints on data lines from clients. An attacker, whether local or remote, can exploit this vulnerability by sending excessively long streams of data. This can lead to the application consuming excessive system memory and CPU resources, potentially resulting in application crashes or system hangs, severely impacting the performance and stability of affected systems.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Gitee Codepecker Lab for reporting this issue.