Executive brief
GLib is a fundamental software library used by many Linux applications to handle data structures and communication. A flaw in how it processes certain data formats (GVariant) could allow an attacker to cause an application to crash or potentially leak a small amount of memory. This is particularly relevant for systems that process untrusted data from the network or via system communication buses like D-Bus.
Technical details
An off-by-one error exists in the gvs_tuple_is_normal function within glib/gvariant-serialiser.c. During an alignment padding check, the code uses a '>' comparison instead of '>=' when validating offsets against the buffer size. This allows a 1-byte out-of-bounds read when the offset equals the value size. An attacker providing specially crafted GVariant data (e.g., via D-Bus or network protocols) can trigger this read. While the impact is primarily a 1-byte information disclosure, it can result in a denial of service (crash) if the out-of-bounds read crosses a memory page boundary. A fix involving a bounds check correction has been proposed.
Affected products
- GNOME GLib
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 10
Timeline
- 2026-01-29: disclosed: Initial report via YesWeHack
- 2026-06-30: advisory: CVE published by Red Hat and NVD