{"id":"AZL-91433","summary":"CVE-2026-58016 affecting package glib for versions less than 2.78.6-11","details":"A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.","modified":"2026-09-03T05:27:10Z","published":"2026-06-30T13:19:17Z","upstream":["CVE-2026-58016"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58016"}],"affected":[{"package":{"name":"glib","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/glib"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.78.6-11"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91433.json"}}],"schema_version":"1.9.0"}