Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-58011— Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime

Quick assessment

Affected
GNOME GLib
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GNOME glib是GNOME基金会开源的一个通用的、可移植的实用程序库。提供了许多有用的数据类型、宏、类型转换、字符串实用程序、文件实用程序、主循环抽象等。 GNOME glib 2.86.5之前版本和2.88.1之前版本存在缓冲区错误漏洞,该漏洞源于在glib/gdatetime.c文件的g_date_time_get_ymd函数中存在2字节越界读取,在处理g_date_time_add_full函数生成的无效GDateTime对象时,可破坏日期输出并导致逻辑错误,可能造成拒绝服务。

CVSS 6.5 · Medium EPSS 0.82% · P56

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 68

VendorProduct Version RangeStatus
GNOME GLib < 2.86.5 affected
< 2.88.1 affected
Red Hat Cert Manager support for Red Hat OpenShift release 1.19 1788348522< * unaffected
1788348571< * unaffected
1788348571< * unaffected
1788348594< * unaffected
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790223279< * unaffected
1790223719< * unaffected
1790272426< * unaffected
1790589998< * unaffected
1790589912< * unaffected
1790589914< * unaffected
1790589855< * unaffected
1790598593< * unaffected
Red Hat Red Hat AI Inference Server 3.2 1790621714< * unaffected
1790621718< * unaffected
1790621713< * unaffected
Red Hat Red Hat Discovery 2 1788205779< * unaffected
1788206196< * unaffected
Red Hat Red Hat Enterprise Linux 10 0:2.80.4-12.el10_2.21< * unaffected
any affected
Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support 0:2.80.4-4.el10_0.17< * unaffected
Red Hat Red Hat Enterprise Linux 6 any affected
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:2.56.1-13.el7_9.1< * unaffected
Red Hat Red Hat Enterprise Linux 8 0:2.70.1-9.el8_10< * unaffected
0:2.56.4-177.el8_10< * unaffected
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:2.56.4-10.el8_4.7< * unaffected
Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On 0:2.56.4-10.el8_4.7< * unaffected
Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 0:2.56.4-158.el8_6.7< * unaffected
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On 0:2.56.4-158.el8_6.7< * unaffected
Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service 0:2.56.4-165.el8_8.2< * unaffected
Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions 0:2.56.4-165.el8_8.2< * unaffected
Red Hat Red Hat Enterprise Linux 9 0:2.68.4-19.el9_8.9< * unaffected
0:2.68.4-19.el9_8.9< * unaffected
any affected
Red Hat Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions 0:2.68.4-7.el9_2.7< * unaffected
Red Hat Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions 0:2.68.4-14.el9_4.8< * unaffected
Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support 0:2.68.4-16.el9_6.7< * unaffected
Red Hat Red Hat Hardened Images any unaffected
Red Hat Red Hat OpenShift AI 3.0 1790276886< * unaffected
1790276884< * unaffected
1790277045< * unaffected
1790276889< * unaffected
1790276974< * unaffected
Red Hat Red Hat OpenShift AI 3.2 1790703497< * unaffected
1790703506< * unaffected
1790703590< * unaffected
1790703568< * unaffected
1790703586< * unaffected
1790703494< * unaffected
Red Hat Red Hat OpenShift AI 3.4 1790703542< * unaffected
1790703539< * unaffected
1790703553< * unaffected
1790703631< * unaffected
1790703597< * unaffected
1790703641< * unaffected
1790703630< * unaffected
1790703541< * unaffected
… +1 more rows
Red Hat Red Hat OpenShift AI 3.5 1790703552< * unaffected
Red Hat Red Hat Update Infrastructure 5 1787241211< * unaffected
1787135742< * unaffected
1787241260< * unaffected
1788880445< * unaffected
1788880464< * unaffected
1788880456< * unaffected
1788765051< * unaffected
1788880581< * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-58011

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5
Vulnerability Title
GNOME glib 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GNOME glib是GNOME基金会开源的一个通用的、可移植的实用程序库。提供了许多有用的数据类型、宏、类型转换、字符串实用程序、文件实用程序、主循环抽象等。 GNOME glib 2.86.5之前版本和2.88.1之前版本存在缓冲区错误漏洞,该漏洞源于在glib/gdatetime.c文件的g_date_time_get_ymd函数中存在2字节越界读取,在处理g_date_time_add_full函数生成的无效GDateTime对象时,可破坏日期输出并导致逻辑错误,可能造成拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
GNOME GLib 0 ~ 2.86.5 -
Red Hat Red Hat Enterprise Linux 10 0:2.80.4-12.el10_2.21 ~ * cpe:/o:redhat:enterprise_linux:10.2
Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support 0:2.80.4-4.el10_0.17 ~ * cpe:/o:redhat:enterprise_linux_eus:10.0
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:2.56.1-13.el7_9.1 ~ * cpe:/o:redhat:rhel_els:7
Red Hat Red Hat Enterprise Linux 8 0:2.70.1-9.el8_10 ~ * cpe:/a:redhat:enterprise_linux:8::crb
Red Hat Red Hat Enterprise Linux 8 0:2.56.4-177.el8_10 ~ * cpe:/a:redhat:enterprise_linux:8::crb
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:2.56.4-10.el8_4.7 ~ * cpe:/o:redhat:rhel_aus:8.4::baseos
Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On 0:2.56.4-10.el8_4.7 ~ * cpe:/o:redhat:rhel_aus:8.4::baseos
Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 0:2.56.4-158.el8_6.7 ~ * cpe:/o:redhat:rhel_aus:8.6::baseos
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On 0:2.56.4-158.el8_6.7 ~ * cpe:/o:redhat:rhel_aus:8.6::baseos
Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service 0:2.56.4-165.el8_8.2 ~ * cpe:/o:redhat:rhel_e4s:8.8::baseos
Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions 0:2.56.4-165.el8_8.2 ~ * cpe:/o:redhat:rhel_e4s:8.8::baseos
Red Hat Red Hat Enterprise Linux 9 0:2.68.4-19.el9_8.9 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:2.68.4-19.el9_8.9 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions 0:2.68.4-7.el9_2.7 ~ * cpe:/a:redhat:rhel_e4s:9.2::appstream
Red Hat Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions 0:2.68.4-14.el9_4.8 ~ * cpe:/a:redhat:rhel_e4s:9.4::appstream
Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support 0:2.68.4-16.el9_6.7 ~ * cpe:/a:redhat:rhel_eus:9.6::appstream
Red Hat Cert Manager support for Red Hat OpenShift release 1.19 1788348522 ~ * cpe:/a:redhat:cert_manager:1.19::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.19 1788348571 ~ * cpe:/a:redhat:cert_manager:1.19::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.19 1788348571 ~ * cpe:/a:redhat:cert_manager:1.19::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.19 1788348594 ~ * cpe:/a:redhat:cert_manager:1.19::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790223279 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790223719 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790272426 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589998 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589912 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589914 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790589855 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.20 1790598593 ~ * cpe:/a:redhat:cert_manager:1.20::el9
Red Hat Red Hat AI Inference Server 3.2 1790621714 ~ * cpe:/a:redhat:ai_inference_server:3.2::el9

II. Public POCs for CVE-2026-58011

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-58011

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-58011 (49)

Other References for CVE-2026-58011 (1)

Other References for CVE-2026-58011 (2)

Same Patch Batch · GNOME · 2026-06-30 · 7 CVEs total

CVE-2026-58016 7.5 HIGH Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
CVE-2026-58014 7.3 HIGH Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"
CVE-2026-58013 6.5 MEDIUM Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"
CVE-2026-58012 6.5 MEDIUM Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_n
CVE-2026-58010 6.5 MEDIUM Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()
CVE-2026-58015 5.9 MEDIUM Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mec

IV. Related Vulnerabilities

V. Comments for CVE-2026-58011

No comments yet


Leave a comment