Fedora alert FEDORA-2026-7bf2937528 (mingw-glib2)
| From: | updates--- via package-announce <package-announce@lists.fedoraproject.org> | |
| To: | package-announce@lists.fedoraproject.org | |
| Subject: | [SECURITY] Fedora 44 Update: mingw-glib2-2.88.2-2.fc44 | |
| Date: | Fri, 17 Jul 2026 00:54:11 +0000 | |
| Message-ID: | <20260717005411.AF1667656A@bastion01.rdu3.fedoraproject.org> | |
| Archive-link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-7bf2937528 2026-07-17 00:51:59.635430+00:00 -------------------------------------------------------------------------------- Name : mingw-glib2 Product : Fedora 44 Version : 2.88.2 Release : 2.fc44 URL : http://www.gtk.org Summary : MinGW Windows GLib2 library Description : MinGW Windows Glib2 library. -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2026-58016. Update to glib-2.88.2. -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 8 2026 Sandro Mani <manisandro@gmail.com> - 2.88.2-2 - Backport fix for CVE-2026-58016 * Thu Jul 2 2026 Sandro Mani <manisandro@gmail.com> - 2.88.2-1 - Update to 2.88.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2494867 - CVE-2026-58010 mingw-glib2: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494867 [ 2 ] Bug #2494871 - CVE-2026-58011 mingw-glib2: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494871 [ 3 ] Bug #2494874 - CVE-2026-58012 mingw-glib2: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494874 [ 4 ] Bug #2494877 - CVE-2026-58013 mingw-glib2: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend" [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494877 [ 5 ] Bug #2494881 - CVE-2026-58014 mingw-glib2: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list" [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494881 [ 6 ] Bug #2494884 - CVE-2026-58015 mingw-glib2: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494884 [ 7 ] Bug #2494886 - CVE-2026-58016 mingw-glib2: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494886 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-7bf2937528' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
