7.5

CVE-2026-58015

Exploit

Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive

A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gnome ≫ Glib Version < 2.88.1
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Version 10.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.418
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
RedHat 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

https://bugzilla.redhat.com/show_bug.cgi?id=2492256
Third Party Advisory
Issue Tracking
https://access.redhat.com/security/cve/CVE-2026-58015
Third Party Advisory
https://gitlab.gnome.org/GNOME/glib/-/issues/3931
Vendor Advisory
Exploit
Issue Tracking
https://access.redhat.com/errata/RHSA-2026:49512
https://access.redhat.com/errata/RHSA-2026:55440
https://access.redhat.com/errata/RHSA-2026:57015
https://access.redhat.com/errata/RHSA-2026:58981
https://access.redhat.com/errata/RHSA-2026:61766
https://access.redhat.com/errata/RHSA-2026:61783
https://access.redhat.com/errata/RHSA-2026:63135
https://access.redhat.com/errata/RHSA-2026:63138
https://access.redhat.com/errata/RHSA-2026:63140
https://access.redhat.com/errata/RHSA-2026:65762
https://access.redhat.com/errata/RHSA-2026:65768
https://access.redhat.com/errata/RHSA-2026:65770
https://access.redhat.com/errata/RHSA-2026:65773
https://access.redhat.com/errata/RHSA-2026:65763
https://access.redhat.com/errata/RHSA-2026:65767
https://access.redhat.com/errata/RHSA-2026:65769
https://access.redhat.com/errata/RHSA-2026:65771
https://access.redhat.com/errata/RHSA-2026:66018
https://access.redhat.com/errata/RHSA-2026:66357
https://access.redhat.com/errata/RHSA-2026:72394
https://access.redhat.com/errata/RHSA-2026:72395
https://access.redhat.com/errata/RHSA-2026:72399
https://access.redhat.com/errata/RHSA-2026:72470
https://access.redhat.com/errata/RHSA-2026:72475
https://access.redhat.com/errata/RHSA-2026:72476
https://access.redhat.com/errata/RHSA-2026:72502
https://access.redhat.com/errata/RHSA-2026:73859
https://access.redhat.com/errata/RHSA-2026:73909
https://access.redhat.com/errata/RHSA-2026:73959
https://access.redhat.com/errata/RHSA-2026:73960
https://access.redhat.com/errata/RHSA-2026:73961
https://access.redhat.com/errata/RHSA-2026:73962
https://access.redhat.com/errata/RHSA-2026:73929
https://access.redhat.com/errata/RHSA-2026:73930
https://access.redhat.com/errata/RHSA-2026:74458
https://access.redhat.com/errata/RHSA-2026:74459
https://access.redhat.com/errata/RHSA-2026:74460
https://access.redhat.com/errata/RHSA-2026:74461
https://access.redhat.com/errata/RHSA-2026:74462
https://access.redhat.com/errata/RHSA-2026:74463
https://access.redhat.com/errata/RHSA-2026:70646
https://access.redhat.com/errata/RHSA-2026:74674
https://access.redhat.com/errata/RHSA-2026:74771
https://access.redhat.com/errata/RHSA-2026:74677
https://access.redhat.com/errata/RHSA-2026:74678
https://access.redhat.com/errata/RHSA-2026:74679
https://access.redhat.com/errata/RHSA-2026:74681
https://access.redhat.com/errata/RHSA-2026:74683
https://access.redhat.com/errata/RHSA-2026:74685
https://access.redhat.com/errata/RHSA-2026:74687
https://access.redhat.com/errata/RHSA-2026:74688
https://access.redhat.com/errata/RHSA-2026:75652
https://access.redhat.com/errata/RHSA-2026:75654
https://access.redhat.com/errata/RHSA-2026:75655
https://access.redhat.com/errata/RHSA-2026:75657
https://access.redhat.com/errata/RHSA-2026:75658
https://access.redhat.com/errata/RHSA-2026:75659
https://access.redhat.com/errata/RHSA-2026:75660
https://access.redhat.com/errata/RHSA-2026:76042