CVE-2026-58016
published 2026-06-30CVE-2026-58016: A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus…
PriorityP347critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.37%
29.5th percentile
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a element nested within other elements like , , or . This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnome | glib | < 2.88.1 | 2.88.1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A flaw was found in GLib.
ghsa_unreviewed·2026-06-30
CVE-2026-58016 [HIGH] CWE-191 A flaw was found in GLib.
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a element nested within other elements like , , or . This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.
VulDB
GNOME GLib up to 2.88.0 gio/gdbusintrospection.c g_dbus_node_info_new_for_xml integer underflow (ID 3932 / EUVD-2026-40319)
vuldb·2026-06-30·CVSS 7.5
CVE-2026-58016 [HIGH] GNOME GLib up to 2.88.0 gio/gdbusintrospection.c g_dbus_node_info_new_for_xml integer underflow (ID 3932 / EUVD-2026-40319)
A vulnerability, which was classified as problematic, was found in GNOME GLib up to 2.88.0. Impacted is the function g_dbus_node_info_new_for_xml of the file gio/gdbusintrospection.c. Such manipulation leads to integer underflow.
This vulnerability is uniquely identified as CVE-2026-58016. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
Red Hat
glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
vendor_redhat·2026-04-08·CVSS 7.5
CVE-2026-58016 [HIGH] CWE-191 glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a element nested within other elements like , , or . This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.
Statement: Any applications processing D-Bus introspection XML input from untrusted sources with g_dbus_node_info_new_for_xml() are vulnerable to this issue. In GLib itself, the gdbus command line tool is the primary vector for local exploitation. However, other applications using the vulnerable function may process untrusted input in a way
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-58016 glib2: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" [fedora-all]
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-58016 [HIGH] CVE-2026-58016 glib2: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" [fedora-all]
CVE-2026-58016 glib2: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A state confusion vulnerability exists in g_dbus_node_info_new_for_xml() in gio/gdbusintrospection.c. When parsing malformed D-Bus introspection XML containing a element nested inside , , , or elements, the parser's internal state becomes inconsistent. The nested closing tag inside the nested steals and resets the shared data->methods (or data->signals/data->properties) array to an empty state. When the outer (or similar) closing tag subsequently calls p
Bugzilla
CVE-2026-58016 glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" [fedora-all]
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-58016 [HIGH] CVE-2026-58016 glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" [fedora-all]
CVE-2026-58016 glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A state confusion vulnerability exists in g_dbus_node_info_new_for_xml() in gio/gdbusintrospection.c. When parsing malformed D-Bus introspection XML containing a element nested inside , , , or elements, the parser's internal state becomes inconsistent. The nested closing tag inside the nested steals and resets the shared data->methods (or data->signals/data->properties) array to an empty state. When the outer (or similar) closing tag subsequently calls pa
Bugzilla
CVE-2026-58016 mingw-glib2: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" [fedora-all]
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-58016 [HIGH] CVE-2026-58016 mingw-glib2: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" [fedora-all]
CVE-2026-58016 mingw-glib2: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A state confusion vulnerability exists in g_dbus_node_info_new_for_xml() in gio/gdbusintrospection.c. When parsing malformed D-Bus introspection XML containing a element nested inside , , , or elements, the parser's internal state becomes inconsistent. The nested closing tag inside the nested steals and resets the shared data->methods (or data->signals/data->properties) array to an empty state. When the outer (or similar) closing tag subsequently c
Bugzilla
CVE-2026-58016 glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
bugzilla·2026-06-24·CVSS 7.5
CVE-2026-58016 [HIGH] CVE-2026-58016 glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
CVE-2026-58016 glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
A state confusion vulnerability exists in g_dbus_node_info_new_for_xml() in gio/gdbusintrospection.c. When parsing malformed D-Bus introspection XML containing a element nested inside , , , or elements, the parser's internal state becomes inconsistent. The nested closing tag inside the nested steals and resets the shared data->methods (or data->signals/data->properties) array to an empty state. When the outer (or similar) closing tag subsequently calls parse_data_get_method(data, FALSE), it accesses pdata[len - 1] with len == 0, causing an unsigned integer underflow (0u - 1 = 0xFFFFFFFF) and a massive out-of-bounds heap read at offset 0xFFFFFFFF * sizeof(gpointer) (~8 GB before the buffer
2026-06-30
Published