Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 471
Alerts This Week
Warning Icon 1 471

openSUSE Leap 16.0 Glib2 Important Out-of-Bounds Issues Fix 2026-21410-1

opensuse
Calendar Grey July 24, 2026
Scroller Opensuse
The recent openSUSE update addresses 6 important issues in glib2, ensuring enhanced system stability and security.
openSUSE has released a security update for glib2 addressing six vulnerabilities, which include out-of-bounds reads and an unsigned integer overflow, applicable to openSUSE Leap 16...

Description

This update for glib2 fixes the following issues:

- CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read

(bsc#1270009).

- CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010).

- CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of-

bounds read (bsc#1270016).

- CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds

read (bsc#1270018).

- CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of-

bounds access (bsc#1270021).

- CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

gio-branding-upstream-2.84.4-160000.4.1

glib2-devel-2.84.4-160000.4.1

glib2-devel-static-2.84.4-160000.4.1

glib2-doc-2.84.4-160000.4.1

glib2-lang-2.84.4-160000.4.1

glib2-tests-devel-2.84.4-160000.4.1

glib2-tools-2.84.4-160000.4.1

libgio-2_0-0-2.84.4-160000.4.1

libgirepository-2_0-0-2.84.4-160000.4.1

libglib-2_0-0-2.84.4-160000.4.1

libgmodule-2_0-0-2.84.4-160000.4.1

libgobject-2_0-0-2.84.4-160000.4.1

libgthread-2_0-0-2.84.4-160000.4.1

typelib-1_0-GIRepository-3_0-2.84.4-160000.4.1

typelib-1_0-GLib-2_0-2.84.4-160000.4.1

typelib-1_0-GLibUnix-2_0-2.84.4-160000.4.1

typelib-1_0-GModule-2_0-2.84.4-160000.4.1

typelib-1_0-GObject-2_0-2.84.4-160000.4.1

typelib-1_0-Gio-2_0-2.84.4-160000.4.1

References

* bsc#1270008

* bsc#1270009

* bsc#1270010

* bsc#1270016

* bsc#1270018

* bsc#1270021

References:

* https://www.suse.com/security/cve/CVE-2026-58010.html

* https://www.suse.com/security/cve/CVE-2026-58011.html

* https://www.suse.com/security/cve/CVE-2026-58012.html

* https://www.suse.com/security/cve/CVE-2026-58013.html

* https://www.suse.com/security/cve/CVE-2026-58014.html

* https://www.suse.com/security/cve/CVE-2026-58016.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21410-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.