RHSA-2026:51183: Important: glib2 security update
GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.Security Fix(es): glib: integer underflow in gio/gdbusintrospection.c via "gdbusnodeinfonewforxml" (CVE-2026-58016) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/glib2to a version that resolves this vulnerability.Fixed in 2.56.1-13.el7_9 - Upgrade
Upgrade
redhat/glib2-debuginfoto a version that resolves this vulnerability.Fixed in 2.56.1-13.el7_9 - Upgrade
Upgrade
redhat/glib2-develto a version that resolves this vulnerability.Fixed in 2.56.1-13.el7_9 - Upgrade
Upgrade
redhat/glib2-docto a version that resolves this vulnerability.Fixed in 2.56.1-13.el7_9 - Upgrade
Upgrade
redhat/glib2-famto a version that resolves this vulnerability.Fixed in 2.56.1-13.el7_9 - Upgrade
Upgrade
redhat/glib2-staticto a version that resolves this vulnerability.Fixed in 2.56.1-13.el7_9 - Upgrade
Upgrade
redhat/glib2-teststo a version that resolves this vulnerability.Fixed in 2.56.1-13.el7_9 - Upgrade
Upgrade
glib2to a version that resolves this vulnerability.Patch CVE-2026-58016 - Compensating control
If immediate patching is not possible, reduce exposure of GLib/GIO D-Bus introspection by restricting access to the D-Bus endpoints/services that rely on gio/gdbusintrospection.c (where g_dbus_node_info_new_for_xml is used).