Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-15588— Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GNOME glib是GNOME基金会开源的一个通用的、可移植的实用程序库。提供了许多有用的数据类型、宏、类型转换、字符串实用程序、文件实用程序、主循环抽象等。 GNOME GLib存在资源管理错误漏洞,该漏洞源于GDBus组件中gdbusauth认证机制未对从客户端读取的数据行实施适当的长度限制,导致未经身份验证的本地或远程攻击者通过发送超长数据流,消耗大量系统内存和CPU,可能导致崩溃或系统挂起。

CVSS 5.3 · Medium EPSS 0.48% · P39

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 70

VendorProduct Version RangeStatus
Red Hat Cert Manager support for Red Hat OpenShift release 1.19 1788348522< * unaffected
1788348571< * unaffected
1788348571< * unaffected
1788348594< * unaffected
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790223279< * unaffected
1790223719< * unaffected
1790272426< * unaffected
1790589998< * unaffected
1790589912< * unaffected
1790589914< * unaffected
1790589855< * unaffected
1790598593< * unaffected
Red Hat Red Hat AI Inference Server 3.2 1790621714< * unaffected
1790621718< * unaffected
1790621713< * unaffected
Red Hat Red Hat Discovery 2 1788205779< * unaffected
1788206196< * unaffected
Red Hat Red Hat Enterprise Linux 10 0:2.80.4-12.el10_2.21< * unaffected
any affected
Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support 0:2.80.4-4.el10_0.17< * unaffected
Red Hat Red Hat Enterprise Linux 6 any affected
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:2.56.1-13.el7_9.1< * unaffected
Red Hat Red Hat Enterprise Linux 8 0:2.56.4-177.el8_10< * unaffected
any affected
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:2.56.4-10.el8_4.7< * unaffected
Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On 0:2.56.4-10.el8_4.7< * unaffected
Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 0:2.56.4-158.el8_6.7< * unaffected
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On 0:2.56.4-158.el8_6.7< * unaffected
Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service 0:2.56.4-165.el8_8.2< * unaffected
Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions 0:2.56.4-165.el8_8.2< * unaffected
Red Hat Red Hat Enterprise Linux 9 0:2.68.4-19.el9_8.9< * unaffected
0:2.68.4-19.el9_8.9< * unaffected
any affected
Red Hat Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions 0:2.68.4-7.el9_2.7< * unaffected
Red Hat Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions 0:2.68.4-14.el9_4.8< * unaffected
Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support 0:2.68.4-16.el9_6.7< * unaffected
Red Hat Red Hat Hardened Images 2.89.1-1.1.hum1< * unaffected
2.89.1-1.2.hum1< * unaffected
2.89.2-2.hum1< * unaffected
Red Hat Red Hat OpenShift AI 3.0 1790276886< * unaffected
1790276884< * unaffected
1790277045< * unaffected
1790276889< * unaffected
1790276974< * unaffected
Red Hat Red Hat OpenShift AI 3.2 1790703497< * unaffected
1790703506< * unaffected
1790703590< * unaffected
1790703568< * unaffected
1790703586< * unaffected
1790703494< * unaffected
Red Hat Red Hat OpenShift AI 3.4 1790703542< * unaffected
1790703539< * unaffected
1790703553< * unaffected
1790703631< * unaffected
1790703597< * unaffected
1790703641< * unaffected
1790703630< * unaffected
1790703541< * unaffected
… +1 more rows
Red Hat Red Hat OpenShift AI 3.5 1790703552< * unaffected
Red Hat Red Hat OpenShift Container Platform 4 any affected
any affected
Red Hat Red Hat Update Infrastructure 5 1787241211< * unaffected
1787135742< * unaffected
1787241260< * unaffected
1788880445< * unaffected
1788880464< * unaffected
1788880456< * unaffected
1788765051< * unaffected
1788880581< * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-15588

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering
Source: CVE Program / CVE List V5
Vulnerability Description
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5
Vulnerability Title
GNOME GLib 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GNOME glib是GNOME基金会开源的一个通用的、可移植的实用程序库。提供了许多有用的数据类型、宏、类型转换、字符串实用程序、文件实用程序、主循环抽象等。 GNOME GLib存在资源管理错误漏洞,该漏洞源于GDBus组件中gdbusauth认证机制未对从客户端读取的数据行实施适当的长度限制,导致未经身份验证的本地或远程攻击者通过发送超长数据流,消耗大量系统内存和CPU,可能导致崩溃或系统挂起。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 0:2.80.4-12.el10_2.21 ~ * cpe:/o:redhat:enterprise_linux:10.2
Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support 0:2.80.4-4.el10_0.17 ~ * cpe:/o:redhat:enterprise_linux_eus:10.0
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:2.56.1-13.el7_9.1 ~ * cpe:/o:redhat:rhel_els:7
Red Hat Red Hat Enterprise Linux 8 0:2.56.4-177.el8_10 ~ * cpe:/a:redhat:enterprise_linux:8::crb
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:2.56.4-10.el8_4.7 ~ * cpe:/o:redhat:rhel_aus:8.4::baseos
Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On 0:2.56.4-10.el8_4.7 ~ * cpe:/o:redhat:rhel_aus:8.4::baseos
Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 0:2.56.4-158.el8_6.7 ~ * cpe:/o:redhat:rhel_aus:8.6::baseos
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On 0:2.56.4-158.el8_6.7 ~ * cpe:/o:redhat:rhel_aus:8.6::baseos
Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service 0:2.56.4-165.el8_8.2 ~ * cpe:/o:redhat:rhel_e4s:8.8::baseos
Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions 0:2.56.4-165.el8_8.2 ~ * cpe:/o:redhat:rhel_e4s:8.8::baseos
Red Hat Red Hat Enterprise Linux 9 0:2.68.4-19.el9_8.9 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:2.68.4-19.el9_8.9 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions 0:2.68.4-7.el9_2.7 ~ * cpe:/a:redhat:rhel_e4s:9.2::appstream
Red Hat Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions 0:2.68.4-14.el9_4.8 ~ * cpe:/a:redhat:rhel_e4s:9.4::appstream
Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support 0:2.68.4-16.el9_6.7 ~ * cpe:/a:redhat:rhel_eus:9.6::appstream
Red Hat Cert Manager support for Red Hat OpenShift release 1.19 1788348522 ~ * cpe:/a:redhat:cert_manager:1.19::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.19 1788348571 ~ * cpe:/a:redhat:cert_manager:1.19::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.19 1788348571 ~ * cpe:/a:redhat:cert_manager:1.19::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.19 1788348594 ~ * cpe:/a:redhat:cert_manager:1.19::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790223279 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790223719 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790272426 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589998 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589912 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589914 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589855 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790598593 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Red Hat AI Inference Server 3.2 1790621714 ~ * cpe:/a:redhat:ai_inference_server:3.2::el9
Red Hat Red Hat AI Inference Server 3.2 1790621718 ~ * cpe:/a:redhat:ai_inference_server:3.2::el9
Red Hat Red Hat AI Inference Server 3.2 1790621713 ~ * cpe:/a:redhat:ai_inference_server:3.2::el9

II. Public POCs for CVE-2026-15588

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15588

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-15588 (51)

Other References for CVE-2026-15588 (1)

Other References for CVE-2026-15588 (2)

Same Patch Batch · Red Hat · 2026-07-20 · 8 CVEs total

CVE-2026-16242 9.4 CRITICAL Hypershift: konnectivity proxy-server accepts agent connections without validating client
CVE-2026-12701 9.0 CRITICAL Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemex
CVE-2026-64612 7.5 HIGH Libcupsfilters: cups-filters: libcupsfilters: cups image filter process abort via malforme
CVE-2026-12080 7.3 HIGH Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add
CVE-2026-15813 6.5 MEDIUM Kronosnet: kronosnet: memory corruption and out-of-bounds access via malformed network pac
CVE-2026-16277 6.5 MEDIUM Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()
CVE-2026-16254 4.3 MEDIUM Claircore: claircore: denial of service via out-of-bounds slice in claircore's apk install

IV. Related Vulnerabilities

V. Comments for CVE-2026-15588

No comments yet


Leave a comment