Buffer Over-Read Vulnerability in GLib Affecting GNOME Software
CVE-2026-58012
Key Information:
- Vendor
Gnome
- Status
- Vendor
- CVE Published:
- 30 June 2026
What is CVE-2026-58012?
A vulnerability exists in GLib that can lead to a buffer over-read in the g_regex_replace function when the G_REGEX_RAW compile flag is used along with case-change replacement escapes. This issue arises because the string_append function handles matched substrings with UTF-8 functions that erroneously rely on valid UTF-8 input, even when dealing with raw byte strings. As a result, this flaw may allow for a minor information disclosure of 1-5 bytes and could also lead to a potential denial of service if the buffer over-read impacts a page boundary.
Affected Version(s)
Cert Manager support for Red Hat OpenShift release 1.19 1788348522
Cert Manager support for Red Hat OpenShift release 1.19 1788348571
Cert Manager support for Red Hat OpenShift release 1.19 1788348571
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved