Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Important: glib2 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:42090", "synopsis": "Important: glib2 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for glib2.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.\n\nSecurity Fix(es):\n\n* glib: integer underflow in gio/gdbusintrospection.c via \"g_dbus_node_info_new_for_xml\" (CVE-2026-58016)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2492257", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2492257", "description": ""}], "cves": [{"name": "CVE-2026-58016", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-58016", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-191"}], "references": [], "publishedAt": "2026-07-21T06:00:44.552120Z", "rpms": {"Rocky Linux 8": {"nvras": ["glib2-0:2.56.4-170.el8_10.aarch64.rpm", "glib2-0:2.56.4-170.el8_10.i686.rpm", "glib2-0:2.56.4-170.el8_10.src.rpm", "glib2-0:2.56.4-170.el8_10.x86_64.rpm", "glib2-debuginfo-0:2.56.4-170.el8_10.aarch64.rpm", "glib2-debuginfo-0:2.56.4-170.el8_10.i686.rpm", "glib2-debuginfo-0:2.56.4-170.el8_10.x86_64.rpm", "glib2-debugsource-0:2.56.4-170.el8_10.aarch64.rpm", "glib2-debugsource-0:2.56.4-170.el8_10.i686.rpm", "glib2-debugsource-0:2.56.4-170.el8_10.x86_64.rpm","glib2-devel-0:2.56.4-170.el8_10.aarch64.rpm", "glib2-devel-0:2.56.4-170.el8_10.i686.rpm", "glib2-devel-0:2.56.4-170.el8_10.x86_64.rpm", "glib2-devel-debuginfo-0:2.56.4-170.el8_10.aarch64.rpm", "glib2-devel-debuginfo-0:2.56.4-170.el8_10.i686.rpm", "glib2-devel-debuginfo-0:2.56.4-170.el8_10.x86_64.rpm", "glib2-doc-0:2.56.4-170.el8_10.noarch.rpm", "glib2-fam-0:2.56.4-170.el8_10.aarch64.rpm", "glib2-fam-0:2.56.4-170.el8_10.x86_64.rpm", "glib2-fam-debuginfo-0:2.56.4-170.el8_10.aarch64.rpm", "glib2-fam-debuginfo-0:2.56.4-170.el8_10.x86_64.rpm", "glib2-static-0:2.56.4-170.el8_10.aarch64.rpm", "glib2-static-0:2.56.4-170.el8_10.i686.rpm", "glib2-static-0:2.56.4-170.el8_10.x86_64.rpm", "glib2-tests-0:2.56.4-170.el8_10.aarch64.rpm", "glib2-tests-0:2.56.4-170.el8_10.x86_64.rpm", "glib2-tests-debuginfo-0:2.56.4-170.el8_10.aarch64.rpm", "glib2-tests-debuginfo-0:2.56.4-170.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. An important glib2 security update is available for Rocky Linux 8 addressing CVE-2026-58016 with a base score of 7.5.. Rocky Linux, glib2 update, security fixes, integer underflow. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-19148 http://linux.oracle.com/errata/ELSA-2026-19148.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: glib2-2.80.4-12.el10_2.13.x86_64.rpm glib2-devel-2.80.4-12.el10_2.13.x86_64.rpm glib2-doc-2.80.4-12.el10_2.13.x86_64.rpm glib2-static-2.80.4-12.el10_2.13.x86_64.rpm glib2-tests-2.80.4-12.el10_2.13.x86_64.rpm aarch64: glib2-2.80.4-12.el10_2.13.aarch64.rpm glib2-devel-2.80.4-12.el10_2.13.aarch64.rpm glib2-doc-2.80.4-12.el10_2.13.aarch64.rpm glib2-static-2.80.4-12.el10_2.13.aarch64.rpm glib2-tests-2.80.4-12.el10_2.13.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/glib2-2.80.4-12.el10_2.13.src.rpm Related CVEs: CVE-2025-14087 CVE-2025-14512 Description of changes: [2.80.4-13] - Fix CVE-2025-14087 and CVE-2025-14512 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-19566 http://linux.oracle.com/errata/ELSA-2026-19566.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: glib2-2.56.1-9.0.5.el7_9.i686.rpm glib2-2.56.1-9.0.5.el7_9.x86_64.rpm glib2-devel-2.56.1-9.0.5.el7_9.i686.rpm glib2-devel-2.56.1-9.0.5.el7_9.x86_64.rpm glib2-doc-2.56.1-9.0.5.el7_9.noarch.rpm glib2-fam-2.56.1-9.0.5.el7_9.x86_64.rpm glib2-static-2.56.1-9.0.5.el7_9.i686.rpm glib2-static-2.56.1-9.0.5.el7_9.x86_64.rpm glib2-tests-2.56.1-9.0.5.el7_9.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/glib2-2.56.1-9.0.5.el7_9.src.rpm Related CVEs: CVE-2025-14087 Description of changes: [2.56.1-9.0.5] - Fixes CVE-2025-14078 gvariant parser buffer underflow [Orabug: 39418716] [2.56.1-9.0.3] - Fixes CVE-2025-13601 g_escape_uri_string() overflow [Orabug: 38909821] [2.56.1-9.0.1] - Fix overflow of GDBusConnection serial [Orabug: 38666376] _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-19361 http://linux.oracle.com/errata/ELSA-2026-19361.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: glib2-2.68.4-19.el9_8.1.i686.rpm glib2-2.68.4-19.el9_8.1.x86_64.rpm glib2-devel-2.68.4-19.el9_8.1.i686.rpm glib2-devel-2.68.4-19.el9_8.1.x86_64.rpm glib2-doc-2.68.4-19.el9_8.1.noarch.rpm glib2-static-2.68.4-19.el9_8.1.i686.rpm glib2-static-2.68.4-19.el9_8.1.x86_64.rpm glib2-tests-2.68.4-19.el9_8.1.x86_64.rpm aarch64: glib2-2.68.4-19.el9_8.1.aarch64.rpm glib2-devel-2.68.4-19.el9_8.1.aarch64.rpm glib2-doc-2.68.4-19.el9_8.1.noarch.rpm glib2-static-2.68.4-19.el9_8.1.aarch64.rpm glib2-tests-2.68.4-19.el9_8.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/glib2-2.68.4-19.el9_8.1.src.rpm Related CVEs: CVE-2025-14087 CVE-2025-14512 Description of changes: [2.68.4-19.1] - Add patch for CVE-2025-14087 and CVE-2025-14512 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-15953 http://linux.oracle.com/errata/ELSA-2026-15953.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: glib2-2.56.4-169.el8_10.i686.rpm glib2-2.56.4-169.el8_10.x86_64.rpm glib2-devel-2.56.4-169.el8_10.i686.rpm glib2-devel-2.56.4-169.el8_10.x86_64.rpm glib2-doc-2.56.4-169.el8_10.noarch.rpm glib2-fam-2.56.4-169.el8_10.x86_64.rpm glib2-static-2.56.4-169.el8_10.i686.rpm glib2-static-2.56.4-169.el8_10.x86_64.rpm glib2-tests-2.56.4-169.el8_10.x86_64.rpm aarch64: glib2-2.56.4-169.el8_10.aarch64.rpm glib2-devel-2.56.4-169.el8_10.aarch64.rpm glib2-doc-2.56.4-169.el8_10.noarch.rpm glib2-fam-2.56.4-169.el8_10.aarch64.rpm glib2-static-2.56.4-169.el8_10.aarch64.rpm glib2-tests-2.56.4-169.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/glib2-2.56.4-169.el8_10.src.rpm Related CVEs: CVE-2025-14087 CVE-2025-14512 Description of changes: [2.68.4-169] - Add patch for CVE-2025-14087 and CVE-2025-14512 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-15971 http://linux.oracle.com/errata/ELSA-2026-15971.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: glib2-2.68.4-18.el9_7.2.i686.rpm glib2-2.68.4-18.el9_7.2.x86_64.rpm glib2-devel-2.68.4-18.el9_7.2.i686.rpm glib2-devel-2.68.4-18.el9_7.2.x86_64.rpm glib2-doc-2.68.4-18.el9_7.2.noarch.rpm glib2-static-2.68.4-18.el9_7.2.i686.rpm glib2-static-2.68.4-18.el9_7.2.x86_64.rpm glib2-tests-2.68.4-18.el9_7.2.x86_64.rpm aarch64: glib2-2.68.4-18.el9_7.2.aarch64.rpm glib2-devel-2.68.4-18.el9_7.2.aarch64.rpm glib2-doc-2.68.4-18.el9_7.2.noarch.rpm glib2-static-2.68.4-18.el9_7.2.aarch64.rpm glib2-tests-2.68.4-18.el9_7.2.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/glib2-2.68.4-18.el9_7.2.src.rpm Related CVEs: CVE-2025-14087 CVE-2025-14512 Description of changes: [2.68.4-18.2] - Add patch for CVE-2025-14087 and CVE-2025-14512 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-15969 http://linux.oracle.com/errata/ELSA-2026-15969.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: glib2-2.80.4-10.el10_1.13.x86_64.rpm glib2-devel-2.80.4-10.el10_1.13.x86_64.rpm glib2-doc-2.80.4-10.el10_1.13.x86_64.rpm glib2-static-2.80.4-10.el10_1.13.x86_64.rpm glib2-tests-2.80.4-10.el10_1.13.x86_64.rpm aarch64: glib2-2.80.4-10.el10_1.13.aarch64.rpm glib2-devel-2.80.4-10.el10_1.13.aarch64.rpm glib2-doc-2.80.4-10.el10_1.13.aarch64.rpm glib2-static-2.80.4-10.el10_1.13.aarch64.rpm glib2-tests-2.80.4-10.el10_1.13.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/glib2-2.80.4-10.el10_1.13.src.rpm Related CVEs: CVE-2025-14087 CVE-2025-14512 Description of changes: [2.80.4-13] - Fix CVE-2025-14087 and CVE-2025-14512 [2.80.4-12] - Fix NVR [2.80.4-11] - Add patch for CVE-2025-13601 _______________________________________________ El-errata mailing list
Moderate: glib2 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:15969", "synopsis": "Moderate: glib2 security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for glib2.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.\n\nSecurity Fix(es):\n\n* glib: GLib: Buffer underflow in GVariant parser leads to heap corruption (CVE-2025-14087)\n\n* glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow (CVE-2025-14512)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2419093", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2419093", "description": ""}, {"ticket": "2421339", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2421339", "description": ""}], "cves": [{"name": "CVE-2025-14087", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-14087", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L", "cvss3BaseScore": "5.6", "cwe": "CWE-190"}, {"name": "CVE-2025-14512", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-14512", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-190"}], "references": [], "publishedAt": "2026-05-13T12:06:54.356511Z", "rpms": {"Rocky Linux 10": {"nvras":["glib2-devel-0:2.80.4-10.el10_1.13.ppc64le.rpm", "glib2-tests-debuginfo-0:2.80.4-10.el10_1.13.ppc64le.rpm", "glib2-debugsource-0:2.80.4-10.el10_1.13.s390x.rpm", "glib2-debuginfo-0:2.80.4-10.el10_1.13.ppc64le.rpm", "glib2-debugsource-0:2.80.4-10.el10_1.13.ppc64le.rpm", "glib2-tests-0:2.80.4-10.el10_1.13.x86_64.rpm", "glib2-debugsource-0:2.80.4-10.el10_1.13.aarch64.rpm", "glib2-doc-0:2.80.4-10.el10_1.13.aarch64.rpm", "glib2-static-0:2.80.4-10.el10_1.13.ppc64le.rpm", "glib2-doc-0:2.80.4-10.el10_1.13.x86_64.rpm", "glib2-static-0:2.80.4-10.el10_1.13.aarch64.rpm", "glib2-debugsource-0:2.80.4-10.el10_1.13.x86_64.rpm", "glib2-tests-0:2.80.4-10.el10_1.13.s390x.rpm", "glib2-tests-0:2.80.4-10.el10_1.13.aarch64.rpm", "glib2-devel-0:2.80.4-10.el10_1.13.aarch64.rpm", "glib2-devel-0:2.80.4-10.el10_1.13.x86_64.rpm", "glib2-tests-debuginfo-0:2.80.4-10.el10_1.13.x86_64.rpm", "glib2-devel-debuginfo-0:2.80.4-10.el10_1.13.x86_64.rpm", "glib2-doc-0:2.80.4-10.el10_1.13.ppc64le.rpm", "glib2-devel-debuginfo-0:2.80.4-10.el10_1.13.s390x.rpm", "glib2-0:2.80.4-10.el10_1.13.x86_64.rpm", "glib2-doc-0:2.80.4-10.el10_1.13.s390x.rpm", "glib2-0:2.80.4-10.el10_1.13.s390x.rpm", "glib2-debuginfo-0:2.80.4-10.el10_1.13.x86_64.rpm", "glib2-static-0:2.80.4-10.el10_1.13.x86_64.rpm", "glib2-devel-debuginfo-0:2.80.4-10.el10_1.13.ppc64le.rpm", "glib2-0:2.80.4-10.el10_1.13.aarch64.rpm", "glib2-devel-debuginfo-0:2.80.4-10.el10_1.13.aarch64.rpm", "glib2-devel-0:2.80.4-10.el10_1.13.s390x.rpm", "glib2-0:2.80.4-10.el10_1.13.src.rpm", "glib2-tests-debuginfo-0:2.80.4-10.el10_1.13.aarch64.rpm", "glib2-0:2.80.4-10.el10_1.13.ppc64le.rpm", "glib2-debuginfo-0:2.80.4-10.el10_1.13.s390x.rpm", "glib2-static-0:2.80.4-10.el10_1.13.s390x.rpm", "glib2-tests-debuginfo-0:2.80.4-10.el10_1.13.s390x.rpm", "glib2-tests-0:2.80.4-10.el10_1.13.ppc64le.rpm", "glib2-debuginfo-0:2.80.4-10.el10_1.13.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A security advisory update for glib2 on Rocky Linux addresses moderate security issues, including heap corruption.. glib2security, Rocky Linux updates, moderate severity fixes. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.