Denial-of-Service Vulnerability in GLib's GDBus by GNOME
CVE-2026-15588
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 20 July 2026
What is CVE-2026-15588?
A denial-of-service and resource exhaustion issue has been identified in the GDBus component of GLib, due to the gdbusauth authentication mechanism failing to enforce length constraints on data lines from clients. An attacker, whether local or remote, can exploit this vulnerability by sending excessively long streams of data. This can lead to the application consuming excessive system memory and CPU resources, potentially resulting in application crashes or system hangs, severely impacting the performance and stability of affected systems.
Affected Version(s)
Cert Manager support for Red Hat OpenShift release 1.19 1788348522
Cert Manager support for Red Hat OpenShift release 1.19 1788348571
Cert Manager support for Red Hat OpenShift release 1.19 1788348571
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved