{"cves":["CVE-2026-15588","CVE-2026-58010","CVE-2026-58011","CVE-2026-58012","CVE-2026-58013","CVE-2026-58014","CVE-2026-58015"],"cvss":0.0,"database_specific":{"severity":"MODERATE"},"description":"[2.68.4-19.9]\n- Fix CVE-2026-15588: limit D-Bus auth line read length\n\n[2.68.4-19.8]\n- Fix CVE-2026-58010: off-by-one in GVariant tuple offset checking\n- Resolves: RHEL-212157\n\n[2.68.4-19.7]\n- Fix CVE-2026-58012: buffer overflow in gregex.c with G_REGEX_RAW\n- Resolves: RHEL-212217\n\n[2.68.4-19.6]\n- Fix CVE-2026-58011: range validation in g_date_time_add_full()\n- Resolves: RHEL-212194\n\n[2.68.4-19.5]\n- Fix CVE-2026-58013: buffer over-read in GIOChannel with long terminators\n- Resolves: RHEL-212236\n\n[2.68.4-19.4]\n- Fix CVE-2026-58014: heap under-read in g_key_file_get_locale_string_list\n- Resolves: RHEL-190589\n\n[2.68.4-19.3]\n- Fix CVE-2026-58015: validate D-Bus DBUS_COOKIE_SHA1 cookie context\n- Resolves: RHEL-212261","id":"ELSA-2026-55440","ovalId":"oval:com.oracle.elsa:def:202655440","source":"oracle_linux","title":"ELSA-2026-55440:  glib2 security update (MODERATE)","url":"https://linux.oracle.com/errata/ELSA-2026-55440.html"}