CVE-2026-58014Patch(gnome / enterprise_linux)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gnome enterprise_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-193

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • glib

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
enterprise_linuxglib

5 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-30: 1Patch / Workaround · 2026-06-30: 1Technical Details · 2026-06-30: 106-30
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - GLib off-by-one OOB read in g_key_file_get_locale_string_list (CVE-2026-58014) A flaw in GLib’s key file parser affects the g_key_file_get_locale_string_list function in gkeyfile.c when loading a key file containing an empty value. The root cause is an off-by-one error leading to a 1-byte out-of-bounds access (read) while processing locale string lists. An attacker can trigger this by supplying or influencing a crafted .ini-style key file that the target application parses via GLib, requiring no special privileges beyond the ability to get the file processed. If the read crosses a page boundary, it can reliably crash the process, resulting in a denial of service and potential service instability in daemons and desktop apps that ingest untrusted config files. 👉 Affected: glib2, mingw-glib2 (versions with vulnerable gkeyfile.c prior to vendor patches) | Upgrade to vendor-fixed GLib release once available (No fix yet — treat as suspicious)

    Post summary

    GLib’s g_key_file_get_locale_string_list suffers an off‑by‑one out‑of‑bounds read that can crash applications via crafted key files; no exploits are available yet, and users are urged to apply the forthcoming vendor patch.

    0000074
    232 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appgnomeglib---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux6.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--

Explore more