Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-58012— Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()

Quick assessment

Affected
GNOME GLib
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GNOME glib是GNOME基金会开源的一个通用的、可移植的实用程序库。提供了许多有用的数据类型、宏、类型转换、字符串实用程序、文件实用程序、主循环抽象等。 GNOME glib存在缓冲区错误漏洞,该漏洞源于g_regex_replace函数在使用G_REGEX_RAW编译标志和大小写替换转义时,string_append函数使用假设有效UTF-8输入的UTF-8函数处理匹配的子字符串,即使字符串被视为原始字节,可能导致缓冲区过度读取,进而造成1-5字节的信息泄露以及当缓冲区过度读取跨越页面边界时导致

CVSS 6.5 · Medium EPSS 0.85% · P56

Affected Version Matrix 36

VendorProduct Version RangeStatus
GNOME GLib < 2.86.5 affected
< 2.88.1 affected
Red Hat Cert Manager support for Red Hat OpenShift release 1.19 1788348522< * unaffected
1788348571< * unaffected
1788348571< * unaffected
1788348594< * unaffected
Red Hat Red Hat Discovery 2 1788205779< * unaffected
1788206196< * unaffected
Red Hat Red Hat Enterprise Linux 10 0:2.80.4-12.el10_2.21< * unaffected
any affected
Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support 0:2.80.4-4.el10_0.17< * unaffected
Red Hat Red Hat Enterprise Linux 6 any affected
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:2.56.1-13.el7_9.1< * unaffected
Red Hat Red Hat Enterprise Linux 8 0:2.70.1-9.el8_10< * unaffected
0:2.56.4-177.el8_10< * unaffected
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:2.56.4-10.el8_4.7< * unaffected
Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On 0:2.56.4-10.el8_4.7< * unaffected
Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 0:2.56.4-158.el8_6.7< * unaffected
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On 0:2.56.4-158.el8_6.7< * unaffected
Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service 0:2.56.4-165.el8_8.2< * unaffected
Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions 0:2.56.4-165.el8_8.2< * unaffected
Red Hat Red Hat Enterprise Linux 9 0:2.68.4-19.el9_8.9< * unaffected
0:2.68.4-19.el9_8.9< * unaffected
any affected
Red Hat Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions 0:2.68.4-7.el9_2.7< * unaffected
Red Hat Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions 0:2.68.4-14.el9_4.8< * unaffected
Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support 0:2.68.4-16.el9_6.7< * unaffected
Red Hat Red Hat Hardened Images any unaffected
Red Hat Red Hat Update Infrastructure 5 1787241211< * unaffected
1787135742< * unaffected
1787241260< * unaffected
1788880445< * unaffected
1788880464< * unaffected
1788880456< * unaffected
1788765051< * unaffected
1788880581< * unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-58012

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
缓冲区上溢读取
Source: CVE Program / CVE List V5
Vulnerability Title
GNOME glib 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GNOME glib是GNOME基金会开源的一个通用的、可移植的实用程序库。提供了许多有用的数据类型、宏、类型转换、字符串实用程序、文件实用程序、主循环抽象等。 GNOME glib存在缓冲区错误漏洞,该漏洞源于g_regex_replace函数在使用G_REGEX_RAW编译标志和大小写替换转义时,string_append函数使用假设有效UTF-8输入的UTF-8函数处理匹配的子字符串,即使字符串被视为原始字节,可能导致缓冲区过度读取,进而造成1-5字节的信息泄露以及当缓冲区过度读取跨越页面边界时导致
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
GNOME GLib 0 ~ 2.86.5 -
Red Hat Red Hat Enterprise Linux 10 0:2.80.4-12.el10_2.21 ~ * cpe:/o:redhat:enterprise_linux:10.2
Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support 0:2.80.4-4.el10_0.17 ~ * cpe:/o:redhat:enterprise_linux_eus:10.0
Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support 0:2.56.1-13.el7_9.1 ~ * cpe:/o:redhat:rhel_els:7
Red Hat Red Hat Enterprise Linux 8 0:2.70.1-9.el8_10 ~ * cpe:/a:redhat:enterprise_linux:8::crb
Red Hat Red Hat Enterprise Linux 8 0:2.56.4-177.el8_10 ~ * cpe:/a:redhat:enterprise_linux:8::crb
Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support 0:2.56.4-10.el8_4.7 ~ * cpe:/o:redhat:rhel_aus:8.4::baseos
Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On 0:2.56.4-10.el8_4.7 ~ * cpe:/o:redhat:rhel_aus:8.4::baseos
Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support 0:2.56.4-158.el8_6.7 ~ * cpe:/o:redhat:rhel_aus:8.6::baseos
Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On 0:2.56.4-158.el8_6.7 ~ * cpe:/o:redhat:rhel_aus:8.6::baseos
Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service 0:2.56.4-165.el8_8.2 ~ * cpe:/o:redhat:rhel_e4s:8.8::baseos
Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions 0:2.56.4-165.el8_8.2 ~ * cpe:/o:redhat:rhel_e4s:8.8::baseos
Red Hat Red Hat Enterprise Linux 9 0:2.68.4-19.el9_8.9 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9 0:2.68.4-19.el9_8.9 ~ * cpe:/a:redhat:enterprise_linux:9::appstream
Red Hat Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions 0:2.68.4-7.el9_2.7 ~ * cpe:/a:redhat:rhel_e4s:9.2::appstream
Red Hat Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions 0:2.68.4-14.el9_4.8 ~ * cpe:/a:redhat:rhel_e4s:9.4::appstream
Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support 0:2.68.4-16.el9_6.7 ~ * cpe:/a:redhat:rhel_eus:9.6::appstream
Red Hat Cert Manager support for Red Hat OpenShift release 1.19 1788348522 ~ * cpe:/a:redhat:cert_manager:1.19::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.19 1788348571 ~ * cpe:/a:redhat:cert_manager:1.19::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.19 1788348571 ~ * cpe:/a:redhat:cert_manager:1.19::el9
Red Hat Cert Manager support for Red Hat OpenShift release 1.19 1788348594 ~ * cpe:/a:redhat:cert_manager:1.19::el9
Red Hat Red Hat Discovery 2 1788205779 ~ * cpe:/a:redhat:discovery:2::el9
Red Hat Red Hat Discovery 2 1788206196 ~ * cpe:/a:redhat:discovery:2::el9
Red Hat Red Hat Update Infrastructure 5 1787241211 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 1787135742 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 1787241260 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 1788880445 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 1788880464 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 1788880456 ~ * cpe:/a:redhat:rhui:5::el9
Red Hat Red Hat Update Infrastructure 5 1788765051 ~ * cpe:/a:redhat:rhui:5::el9

II. Public POCs for CVE-2026-58012

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-58012

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-58012 (18)

Proof of Concept for CVE-2026-58012 (1)

Other References for CVE-2026-58012 (2)

Same Patch Batch · GNOME · 2026-06-30 · 7 CVEs total

CVE-2026-58016 7.5 HIGH Glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
CVE-2026-58014 7.3 HIGH Glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"
CVE-2026-58011 6.5 MEDIUM Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime
CVE-2026-58013 6.5 MEDIUM Glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"
CVE-2026-58010 6.5 MEDIUM Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()
CVE-2026-58015 5.9 MEDIUM Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mec

IV. Related Vulnerabilities

V. Comments for CVE-2026-58012

No comments yet


Leave a comment