ELSA-2026-49512

ELSA-2026-49512 - mingw-glib2 security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-08-04

Description


[2.70.1-9]
- Fix CVE-2026-58010: off-by-one error in gvs_tuple_is_normal()
Resolves: RHEL-212164

[2.70.1-8]
- Fix CVE-2026-58011: g_date_time_add_full() range validation
Resolves: RHEL-212184

[2.70.1-7]
- Fix CVE-2026-58013: memcmp buffer over-read in giochannel
Resolves: RHEL-212234

[2.70.1-6]
- Fix CVE-2026-58012: buffer overflow in gregex substitutions
Resolves: RHEL-212200

[2.70.1-5]
- Fix CVE-2025-14087: integer overflow in GVariant parser
Resolves: RHEL-154707

[2.70.1-4]
- Fix CVE-2026-58016: D-Bus introspection XML node nesting check
Resolves: RHEL-190617

[2.70.1-3]
- Fix CVE-2026-58014: one-byte heap under-read in mingw-glib2
Resolves: RHEL-190609

[2.70.1-2]
- Fix CVE-2026-58015: D-Bus cookie context path traversal
Resolves: RHEL-212246


Related CVEs


CVE-2025-14087
CVE-2026-58010
CVE-2026-58011
CVE-2026-58012
CVE-2026-58013
CVE-2026-58014
CVE-2026-58015
CVE-2026-58016

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) mingw-glib2-2.70.1-9.el8_10.src.rpmd2d1296aa4c68a4f54677eb527b640d14c6ee8e180308fb22a89b2ae6a5402f8-ol8_aarch64_codeready_builder
Oracle Linux 8 (x86_64) mingw-glib2-2.70.1-9.el8_10.src.rpmd2d1296aa4c68a4f54677eb527b640d14c6ee8e180308fb22a89b2ae6a5402f8-ol8_x86_64_codeready_builder
mingw32-glib2-2.70.1-9.el8_10.noarch.rpm81b75b417fe2cfccd1703f60562bf10978a02749ca1d7d03bc65bc2dec845998-ol8_x86_64_codeready_builder
mingw32-glib2-static-2.70.1-9.el8_10.noarch.rpma797a1a67b068128ad2136ff1a83f37a5280bd0af3bd545fe58acad3125b8058-ol8_x86_64_codeready_builder
mingw64-glib2-2.70.1-9.el8_10.noarch.rpm3e3e860c4f3b51096a0ffeca4779fa98156faee27483bf61ff1d4528911d9f25-ol8_x86_64_codeready_builder
mingw64-glib2-static-2.70.1-9.el8_10.noarch.rpm90093186247e8b7efd5b06b2a9ef85ade9d1d160c61e5011eaf3a017f6f05cfa-ol8_x86_64_codeready_builder



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete