Path Traversal Vulnerability in GLib D-Bus Client Implementation
CVE-2026-58015
Key Information:
- Vendor
Gnome
- Vendor
- CVE Published:
- 30 June 2026
What is CVE-2026-58015?
A vulnerability exists in the D-Bus client-side implementation of the SASL authentication mechanism within GLib. The flaw arises from the failure to validate the cookie_context parameter received from potentially compromised D-Bus servers. This could permit an attacker to execute path traversal sequences, allowing them to trick the client into reading arbitrary files. Consequently, sensitive information could be leaked if the client verifies guessed contents against generated hashes. Effective mitigation requires users to ensure they are operating on updated and secured versions of GLib to prevent unauthorized access to sensitive data.
Affected Version(s)
GLib 0 < 2.88.1
Red Hat Enterprise Linux 8 0:2.70.1-9.el8_10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved