Executive brief
A vulnerability exists in xdgmime, a library used by many Linux applications to identify file types. By tricking a user into placing a specially crafted file in certain system folders, an attacker can cause applications to crash or potentially corrupt system memory. This affects the stability and security of desktop environments and applications that handle file uploads or downloads.
Technical details
A heap-based buffer overflow exists in the _xdg_mime_magic_parse_magic_line() function within xdgmimemagic.c. The flaw is caused by incorrect pointer arithmetic during byte-swapping operations on little-endian systems; specifically, the code uses element-based offsets instead of byte-based offsets when writing swapped values to the heap. An attacker can exploit this by placing a crafted MIME magic file in a user-writable XDG data location (e.g., $XDG_DATA_HOME/mime/magic). When a library like GLib (via g_content_type_guess()) parses this file, it triggers an out-of-bounds write of 2 or 4 bytes, leading to a crash or potential arbitrary code execution.
Affected products
- freedesktop.org xdgmime
- Red Hat glib2 Enterprise Linux 9, 10
- Red Hat webkit2gtk3 Enterprise Linux 8, 9
- Red Hat webkitgtk4 Enterprise Linux 7
Timeline
- 2026-02-14: other: Reported to GNOME via YesWeHack
- 2026-07-17: advisory: NVD and Red Hat published advisory details