Out-of-Bounds Read Vulnerability in GLib Affects Users of GDateTime
CVE-2026-58011

6.5MEDIUM

What is CVE-2026-58011?

An out-of-bounds read vulnerability exists in the GLib library affecting the GDateTime data structure. Specifically, when an invalid GDateTime object is generated using the g_date_time_add_full function, it can lead to an out-of-bounds read of 2 bytes during processing by the g_date_time_get_ymd function. This flaw can corrupt the output of date values and may trigger logic errors within applications, potentially resulting in service disruption or instability.

Affected Version(s)

Cert Manager support for Red Hat OpenShift release 1.19 1788348522

Cert Manager support for Red Hat OpenShift release 1.19 1788348571

Cert Manager support for Red Hat OpenShift release 1.19 1788348571

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank linhlhq for reporting this issue.
.