Executive brief
A security vulnerability has been identified in GLib, a core library used by many Linux-based applications to handle system communications. A malicious server can trick a client application into reading sensitive files from the user's computer by exploiting a flaw in how it handles authentication requests. This could allow an attacker to steal private data by verifying guessed file contents against cryptographic hashes sent back by the victim's system.
Technical details
A path traversal vulnerability exists in GLib's GDBus implementation within `gio/gdbusauthmechanismsha1.c`. The client-side implementation of the `DBUS_COOKIE_SHA1` SASL mechanism fails to validate the `cookie_context` parameter provided by the server, despite D-Bus specifications forbidding path delimiters. An attacker-controlled D-Bus server can provide a crafted `cookie_context` (e.g., using `../` sequences) which `keyring_lookup_entry()` uses in `g_build_filename()` to access files outside the intended `~/.dbus-keyrings/` directory. The client reads the target file and incorporates a portion of its content into a SHA1 hash returned to the server. A remote attacker can then exfiltrate sensitive data by brute-forcing or verifying guessed file contents against the received hash. This is particularly relevant for D-Bus over TCP connections where `EXTERNAL` authentication is unavailable.
Affected products
- GNOME GLib All versions implementing DBUS_COOKIE_SHA1 client-side authentication (including 2.87.2)
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 10
Timeline
- 2026-02-01: disclosed: Reported via YesWeHack to GNOME/GLib
- 2026-06-30: advisory: NVD and Red Hat published advisory details