Back to Security Advisories
High 2026-08-03

Mingw-Glib2 Security Update — AlmaLinux 8 (ALSA-2026:49512)

AlmaLinux 8

GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures. Security Fix(es): * glib: GLib: Buffer underflow in GVar…

GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.

Security Fix(es):

* glib: GLib: Buffer underflow in GVar…

Type:
security

Severity:
important

Release date:
2026-08-03

Description:
GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.

Security Fix(es):

* glib: GLib: Buffer underflow in GVariant parser leads to heap corruption (CVE-2025-14087)
* glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() (CVE-2026-58010)
* glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime (CVE-2026-58011)
* glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() (CVE-2026-58012)
* glib: buffer over-read in glib/giochannel.c via “g_io_channel_read_line_backend” (CVE-2026-58013)
* glib: off-by-one error in glib/gkeyfile.c via “g_key_file_get_locale_string_list” (CVE-2026-58014)
* glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive (CVE-2026-58015)
* glib: integer underflow in gio/gdbusintrospection.c via “g_dbus_node_info_new_for_xml” (CVE-2026-58016)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
noarch mingw64-glib2-static-2.70.1-9.el8_10.noarch.rpm 1326bc1c5b14c11c870d3011b13ed7da6b177412404c85aeef6815454174b36f
noarch mingw32-glib2-2.70.1-9.el8_10.noarch.rpm b8b7ae6a165301957fa063fbd0807a55cfafb4021cc8f71d7b16b937c832ed91
noarch mingw32-glib2-static-2.70.1-9.el8_10.noarch.rpm d2cd96cb052c09e5069ef47154b42b5c277de55effa4a5f361e3e247050c7fce
noarch mingw64-glib2-2.70.1-9.el8_10.noarch.rpm ece1e27260093e72198fb221cd4c48026b68b3d2987ee53723bcbb103c95b41a

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo dnf update
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System