
🚨 HIGH - GLib off-by-one OOB read in g_key_file_get_locale_string_list (CVE-2026-58014) A flaw in GLib’s key file parser affects the g_key_file_get_locale_string_list function in gkeyfile.c when loading a key file containing an empty value. The root cause is an off-by-one error leading to a 1-byte out-of-bounds access (read) while processing locale string lists. An attacker can trigger this by supplying or influencing a crafted .ini-style key file that the target application parses via GLib, requiring no special privileges beyond the ability to get the file processed. If the read crosses a page boundary, it can reliably crash the process, resulting in a denial of service and potential service instability in daemons and desktop apps that ingest untrusted config files. 👉 Affected: glib2, mingw-glib2 (versions with vulnerable gkeyfile.c prior to vendor patches) | Upgrade to vendor-fixed GLib release once available (No fix yet — treat as suspicious)
Post summary
GLib’s g_key_file_get_locale_string_list suffers an off‑by‑one out‑of‑bounds read that can crash applications via crafted key files; no exploits are available yet, and users are urged to apply the forthcoming vendor patch.
