CVE-2026-1485: Glib: glib: local denial of service via buffer underflow in content type parsing

Published Jan 27, 2026
·
Updated

A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.

Other sources

Buffer Underflow vulnerability in GLib’s content type parsing logic. The issue is caused by storing the length of a header line in a signed integer, allowing integer wraparound for extremely large inputs. This leads to pointer underflow and out-of-bounds memory access in parseheader(). Exploitation requires a user to install or process a maliciously crafted treemagic file, limiting the practical impact to local denial of service or application instability.

Red Hat

Affected Software

1 affected component
Gnome GLib

Event History

Jan 27, 2026
Data Sourced
via Red Hat·01:13 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·01:43 PM
Data Sourced
via MITRE·01:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-1485?

CVE-2026-1485 has a severity rating that indicates it can lead to a local denial of service.

2

How do I fix CVE-2026-1485?

To fix CVE-2026-1485, update to the latest version of the GLib library where the vulnerability has been addressed.

3

What causes the buffer underflow in CVE-2026-1485?

The buffer underflow in CVE-2026-1485 is caused by the way the length of a header line is stored in a signed integer, leading to potential integer wraparound.

4

Is CVE-2026-1485 easily exploitable?

CVE-2026-1485 is considered to be a local denial of service vulnerability, which typically requires local access to exploit.

5

Which software is affected by CVE-2026-1485?

CVE-2026-1485 affects the Gnome GLib library.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203