Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:65773 - Security Advisory
Issued:
2026-09-09
Updated:
2026-09-09

RHSA-2026:65773 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: glib2 security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for glib2 is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.

Security Fix(es):

  • glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() (CVE-2026-58010)
  • glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime (CVE-2026-58011)
  • glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() (CVE-2026-58012)
  • glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" (CVE-2026-58013)
  • glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" (CVE-2026-58014)
  • glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive (CVE-2026-58015)
  • GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering (CVE-2026-15588)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2492243 - CVE-2026-58010 glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()
  • BZ - 2492245 - CVE-2026-58011 glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime
  • BZ - 2492247 - CVE-2026-58012 glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()
  • BZ - 2492248 - CVE-2026-58013 glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"
  • BZ - 2492255 - CVE-2026-58014 glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"
  • BZ - 2492256 - CVE-2026-58015 glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive
  • BZ - 2499675 - CVE-2026-15588 GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering

CVEs

  • CVE-2026-15588
  • CVE-2026-58010
  • CVE-2026-58011
  • CVE-2026-58012
  • CVE-2026-58013
  • CVE-2026-58014
  • CVE-2026-58015

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
glib2-2.56.1-13.el7_9.1.src.rpm SHA-256: ef1f33e19a1af4c136d93f042ddcc8e9cfb947236d223ef9050e45114b9c1284
x86_64
glib2-2.56.1-13.el7_9.1.i686.rpm SHA-256: 7d69cf40602886516201d7aabadfb3c222a8dc8f1cfefee8a2ece70dbe6c0df6
glib2-2.56.1-13.el7_9.1.x86_64.rpm SHA-256: 70458e44c4c4b087337a82cb3cc302c77e31f235f281bfdd3a9f27df2d64f529
glib2-debuginfo-2.56.1-13.el7_9.1.i686.rpm SHA-256: 355ae67057646364b6bde27c5b3bceae820c5385b8a6dc4a169765f8c2df7769
glib2-debuginfo-2.56.1-13.el7_9.1.i686.rpm SHA-256: 355ae67057646364b6bde27c5b3bceae820c5385b8a6dc4a169765f8c2df7769
glib2-debuginfo-2.56.1-13.el7_9.1.x86_64.rpm SHA-256: 3894f994711006692db535104c1ae3078e19245cee64704ad6d5a9b148469782
glib2-debuginfo-2.56.1-13.el7_9.1.x86_64.rpm SHA-256: 3894f994711006692db535104c1ae3078e19245cee64704ad6d5a9b148469782
glib2-devel-2.56.1-13.el7_9.1.i686.rpm SHA-256: c61e4564884760dfa3ce1ee0a13704f4952ec6d6f47709bd6210e2b9751f86cc
glib2-devel-2.56.1-13.el7_9.1.x86_64.rpm SHA-256: 461657adc2cef276573a5d7d2bd65f37ac7ff46d82aba83b4729520e0b284d5c
glib2-doc-2.56.1-13.el7_9.1.noarch.rpm SHA-256: a37c2748852a6773d232bfd6ef0b703c1d01d313b0794857a83917fdd516ad7a
glib2-fam-2.56.1-13.el7_9.1.x86_64.rpm SHA-256: 82136de5902573d935b75a3520df721c061f84d7e537c6460a99639ed236b137
glib2-static-2.56.1-13.el7_9.1.i686.rpm SHA-256: 8d3c6bba64dc4d78dba9eddd47de87ee65d593989faac1962b4a8326f48d01d4
glib2-static-2.56.1-13.el7_9.1.x86_64.rpm SHA-256: f30a36708c37a096e9da42d0ae6da300ea37824286d9da2c1defec673d67a9e9
glib2-tests-2.56.1-13.el7_9.1.x86_64.rpm SHA-256: dd8f40952f9a90790c5d091cea05aefd4d4dea0183c8be48bbc4ea0d9d3568ca

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
glib2-2.56.1-13.el7_9.1.src.rpm SHA-256: ef1f33e19a1af4c136d93f042ddcc8e9cfb947236d223ef9050e45114b9c1284
s390x
glib2-2.56.1-13.el7_9.1.s390.rpm SHA-256: 583de0a2a648b344c66a8a770bbed9ae42a14c3b20ddff703e8ed292e4b0baa1
glib2-2.56.1-13.el7_9.1.s390x.rpm SHA-256: b3076a20a7c6cce46a98991decb25ee486948bb08b60a13e95520228f07cfe11
glib2-debuginfo-2.56.1-13.el7_9.1.s390.rpm SHA-256: 382e2b26274b0d77bd4e7dabc70b291b70f936666a36e1be04b1c9293f9c8799
glib2-debuginfo-2.56.1-13.el7_9.1.s390.rpm SHA-256: 382e2b26274b0d77bd4e7dabc70b291b70f936666a36e1be04b1c9293f9c8799
glib2-debuginfo-2.56.1-13.el7_9.1.s390x.rpm SHA-256: e5d9c75fd56fc8eafe7426fd5b43fa018c1c893db187bb905dd4e5d4bf10a01a
glib2-debuginfo-2.56.1-13.el7_9.1.s390x.rpm SHA-256: e5d9c75fd56fc8eafe7426fd5b43fa018c1c893db187bb905dd4e5d4bf10a01a
glib2-devel-2.56.1-13.el7_9.1.s390.rpm SHA-256: 19fae58987313d0d2a4184d93f07f1966ad057930ffc900043166fe3d75f22c7
glib2-devel-2.56.1-13.el7_9.1.s390x.rpm SHA-256: 9ee0611562246c4620d9a88d72e4f4e58cda5142c656b261092cf1b11c798ea0
glib2-doc-2.56.1-13.el7_9.1.noarch.rpm SHA-256: a37c2748852a6773d232bfd6ef0b703c1d01d313b0794857a83917fdd516ad7a
glib2-fam-2.56.1-13.el7_9.1.s390x.rpm SHA-256: 951752309394fdaadc5c06a6caa69404419a78697aa8f970e86ccbde2c9ba885
glib2-static-2.56.1-13.el7_9.1.s390.rpm SHA-256: c29f3eaf389f15b927456edd8fd789d64e0013693ab0f7f19b119efb8eea838b
glib2-static-2.56.1-13.el7_9.1.s390x.rpm SHA-256: 23bc54777789fcda4b7152ce0900863c6ab6df08e0cb1401ae20dc729f55b50d
glib2-tests-2.56.1-13.el7_9.1.s390x.rpm SHA-256: 52c15229e06b6ec590c255b9dd5edb180fbbdac31b416324135df44aa18f6aa0

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
glib2-2.56.1-13.el7_9.1.src.rpm SHA-256: ef1f33e19a1af4c136d93f042ddcc8e9cfb947236d223ef9050e45114b9c1284
ppc64
glib2-2.56.1-13.el7_9.1.ppc.rpm SHA-256: aa7c7be28eb7dcfc0170699d6393cb3f3a8ccf085bf93b0a0a5c1793711e7305
glib2-2.56.1-13.el7_9.1.ppc64.rpm SHA-256: cc095adb870f059187c1eae4d6e045528f2010044d8f3dbe98c274bb9b8b449f
glib2-debuginfo-2.56.1-13.el7_9.1.ppc.rpm SHA-256: 859d2ed29d5c0a5960850e464933b8cab153dc0f6dcd7f6d87c540bb567afe69
glib2-debuginfo-2.56.1-13.el7_9.1.ppc.rpm SHA-256: 859d2ed29d5c0a5960850e464933b8cab153dc0f6dcd7f6d87c540bb567afe69
glib2-debuginfo-2.56.1-13.el7_9.1.ppc64.rpm SHA-256: d7c74ea958d70f6efa3f4446d9e7383b152cf4cb1238d9d067a09b52d2e54254
glib2-debuginfo-2.56.1-13.el7_9.1.ppc64.rpm SHA-256: d7c74ea958d70f6efa3f4446d9e7383b152cf4cb1238d9d067a09b52d2e54254
glib2-devel-2.56.1-13.el7_9.1.ppc.rpm SHA-256: 6628dbad715a235c164eade43e4dbc30e37281a195e061670ec223d36c4555e2
glib2-devel-2.56.1-13.el7_9.1.ppc64.rpm SHA-256: f8f8526f37874b8590fc57571ca4c6f69beca75e07efafb7773f71d565833e3b
glib2-doc-2.56.1-13.el7_9.1.noarch.rpm SHA-256: a37c2748852a6773d232bfd6ef0b703c1d01d313b0794857a83917fdd516ad7a
glib2-fam-2.56.1-13.el7_9.1.ppc64.rpm SHA-256: 2735ae17f2de1014a174aa1e1bbcedf9ac16be7cd049173a9d7097b2f30736ba
glib2-static-2.56.1-13.el7_9.1.ppc.rpm SHA-256: b200cf7ad5e078af38a61aecbee247de9f882620713113af7d843ff61fb43353
glib2-static-2.56.1-13.el7_9.1.ppc64.rpm SHA-256: 103b777f62eece6eb8685c530c621fd6e095e94cae1b1fdbb32559311c509d57
glib2-tests-2.56.1-13.el7_9.1.ppc64.rpm SHA-256: 291c9a9c2d4452bad0a2433f51d7faacdac886b91136f4f75db455b4a0cc6bee

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
glib2-2.56.1-13.el7_9.1.src.rpm SHA-256: ef1f33e19a1af4c136d93f042ddcc8e9cfb947236d223ef9050e45114b9c1284
ppc64le
glib2-2.56.1-13.el7_9.1.ppc64le.rpm SHA-256: d0d8abec78f781fd8de111fb4da2e1f297ca34cede2e0be2aa4a809eda34da13
glib2-debuginfo-2.56.1-13.el7_9.1.ppc64le.rpm SHA-256: 3b61c73d5aa89051172a6a30e96b87ea0d0c72e6baddaf0b092ccc38431d76b5
glib2-debuginfo-2.56.1-13.el7_9.1.ppc64le.rpm SHA-256: 3b61c73d5aa89051172a6a30e96b87ea0d0c72e6baddaf0b092ccc38431d76b5
glib2-devel-2.56.1-13.el7_9.1.ppc64le.rpm SHA-256: f5ec3716afc7a4fe27f0543d3b1eec0b2eadca8519a47144c426cab95492c09b
glib2-doc-2.56.1-13.el7_9.1.noarch.rpm SHA-256: a37c2748852a6773d232bfd6ef0b703c1d01d313b0794857a83917fdd516ad7a
glib2-fam-2.56.1-13.el7_9.1.ppc64le.rpm SHA-256: 3519e1ec35b695fd0b0e8dfb184570f7e2a262a0d1fb485e6845cb2a80c7600b
glib2-static-2.56.1-13.el7_9.1.ppc64le.rpm SHA-256: ffea3409572af20152e402d26ba8af757f78f901d9161ed53c41795b74ca65f0
glib2-tests-2.56.1-13.el7_9.1.ppc64le.rpm SHA-256: 0f156fbf8a52289c333fc27ffb30cb36043da31323238969f614576d6e808c66

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility