Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 581
Alerts This Week
Warning Icon 1 581

openSUSE glib2 Important Buffer Overflow Issues Fixed 2026-3341-1

opensuse
Calendar Grey July 28, 2026
Scroller Opensuse
New SUSE security patch addresses multiple vulnerabilities in glib2 to enhance system protection and stability.
SUSE has released a security update for glib2 addressing six vulnerabilities that could lead to out-of-bounds reads and an unsigned integer overflow, impacting several SUSE product...

Description

This update for glib2 fixes the following issues:

* CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could

cause a 1-byte out-of-bounds read (bsc#1270009).

* CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a

2-byte out-of-bounds read (bsc#1270010).

* CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-

change replacements could cause an out-of- bounds read (bsc#1270016).

* CVE-2026-58013: multi-byte custom line terminator in

g_io_channel_read_line_backend could trigger an out-of-bounds read

(bsc#1270018).

* CVE-2026-58014: processing empty key file values in

g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access

(bsc#1270021).

* CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned

integer overflow (bsc#1270008).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* Basesystem Module 15-SP7

zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3341=1

* SUSE Linux Enterprise Server 15 SP6 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3341=1

* openSUSE Leap 15.6

zypper in -t patch SUSE-2026-3341=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3341=1

Package List

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)

* libgio-2_0-0-2.78.6-150600.4.38.1

* libglib-2_0-0-debuginfo-2.78.6-150600.4.38.1

* glib2-tests-devel-2.78.6-150600.4.38.1

* libgthread-2_0-0-2.78.6-150600.4.38.1

* glib2-tools-debuginfo-2.78.6-150600.4.38.1

* libgobject-2_0-0-2.78.6-150600.4.38.1

* glib2-tools-2.78.6-150600.4.38.1

* libgobject-2_0-0-debuginfo-2.78.6-150600.4.38.1

* glib2-tests-devel-debuginfo-2.78.6-150600.4.38.1

* libgio-2_0-0-debuginfo-2.78.6-150600.4.38.1

* libgmodule-2_0-0-debuginfo-2.78.6-150600.4.38.1

* glib2-debugsource-2.78.6-150600.4.38.1

* glib2-devel-2.78.6-150600.4.38.1

* glib2-doc-2.78.6-150600.4.38.1

* glib2-devel-static-2.78.6-150600.4.38.1

* libgmodule-2_0-0-2.78.6-150600.4.38.1

* glib2-devel-debuginfo-2.78.6-150600.4.38.1

* libglib-2_0-0-2.78.6-150600.4.38.1

* libgthread-2_0-0-debuginfo-2.78.6-150600.4.38.1

* openSUSE Leap 15.6 (aarch64_ilp32)

* libgmodule-2_0-0-64bit-debuginfo-2.78.6-150600.4.38.1

* glib2-devel-64bit-debuginfo-2.78.6-150600.4.38.1

*...

Read the Full Advisory

References

* bsc#1270008

* bsc#1270009

* bsc#1270010

* bsc#1270016

* bsc#1270018

* bsc#1270021

## References:

* https://www.suse.com/security/cve/CVE-2026-58010.html

* https://www.suse.com/security/cve/CVE-2026-58011.html

* https://www.suse.com/security/cve/CVE-2026-58012.html

* https://www.suse.com/security/cve/CVE-2026-58013.html

* https://www.suse.com/security/cve/CVE-2026-58014.html

* https://www.suse.com/security/cve/CVE-2026-58016.html

* https://bugzilla.suse.com/show_bug.cgi?id=1270008

* https://bugzilla.suse.com/show_bug.cgi?id=1270009

* https://bugzilla.suse.com/show_bug.cgi?id=1270010

* https://bugzilla.suse.com/show_bug.cgi?id=1270016

* https://bugzilla.suse.com/show_bug.cgi?id=1270018

* https://bugzilla.suse.com/show_bug.cgi?id=1270021

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3341-1
Release Date: 2026-07-28T10:09:32Z

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.