elsa-2026-49512

oracle_linux
Description

[2.70.1-9] - Fix CVE-2026-58010: off-by-one error in gvs_tuple_is_normal() Resolves: RHEL-212164 [2.70.1-8] - Fix CVE-2026-58011: g_date_time_add_full() range validation Resolves: RHEL-212184 [2.70.1-7] - Fix CVE-2026-58013: memcmp buffer over-read in giochannel Resolves: RHEL-212234 [2.70.1-6] - Fix CVE-2026-58012: buffer overflow in gregex substitutions Resolves: RHEL-212200 [2.70.1-5] - Fix CVE-2025-14087: integer overflow in GVariant parser Resolves: RHEL-154707 [2.70.1-4] - Fix CVE-2026-58016: D-Bus introspection XML node nesting check Resolves: RHEL-190617 [2.70.1-3] - Fix CVE-2026-58014: one-byte heap under-read in mingw-glib2 Resolves: RHEL-190609 [2.70.1-2] - Fix CVE-2026-58015: D-Bus cookie context path traversal Resolves: RHEL-212246

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2025-14087",
    "CVE-2026-58010",
    "CVE-2026-58011",
    "CVE-2026-58012",
    "CVE-2026-58013",
    "CVE-2026-58014",
    "CVE-2026-58015",
    "CVE-2026-58016"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[2.70.1-9]\n- Fix CVE-2026-58010: off-by-one error in gvs_tuple_is_normal()\n  Resolves: RHEL-212164\n\n[2.70.1-8]\n- Fix CVE-2026-58011: g_date_time_add_full() range validation\n  Resolves: RHEL-212184\n\n[2.70.1-7]\n- Fix CVE-2026-58013: memcmp buffer over-read in giochannel\n  Resolves: RHEL-212234\n\n[2.70.1-6]\n- Fix CVE-2026-58012: buffer overflow in gregex substitutions\n  Resolves: RHEL-212200\n\n[2.70.1-5]\n- Fix CVE-2025-14087: integer overflow in GVariant parser\n  Resolves: RHEL-154707\n\n[2.70.1-4]\n- Fix CVE-2026-58016: D-Bus introspection XML node nesting check\n  Resolves: RHEL-190617\n\n[2.70.1-3]\n- Fix CVE-2026-58014: one-byte heap under-read in mingw-glib2\n  Resolves: RHEL-190609\n\n[2.70.1-2]\n- Fix CVE-2026-58015: D-Bus cookie context path traversal\n  Resolves: RHEL-212246",
  "id": "ELSA-2026-49512",
  "ovalId": "oval:com.oracle.elsa:def:202649512",
  "source": "oracle_linux",
  "title": "ELSA-2026-49512:  mingw-glib2 security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-49512.html"
}
View JSON API Download JSON