{"id":"USN-8794-1","summary":"glib2.0 vulnerabilities","details":"It was discovered that GLib's GDBus authentication mechanism failed to\nenforce length limitations on data lines read from a client. An\nunauthenticated attacker could exploit this to cause a denial of service\nvia resource exhaustion. (CVE-2026-15588)\n\nIt was discovered that the xdgmime library in GLib had a heap-based\nbuffer overflow. An attacker-controlled MIME magic file could cause an\nout-of-bounds write on little-endian systems. (CVE-2026-16118)\n\nIt was discovered that GLib had an off-by-one error in the GVariant\nserialiser. An attacker could use this to cause an out-of-bounds read,\nleading to information disclosure or a denial of service.\n(CVE-2026-58010)\n\nIt was discovered that GLib had an out-of-bounds read in GDateTime. An\nattacker could use this to corrupt date output and cause a denial of\nservice. (CVE-2026-58011)\n\nIt was discovered that GLib's g_regex_replace() function had a buffer\nover-read when used with the G_REGEX_RAW flag. An attacker could use\nthis to cause information disclosure or a denial of service.\n(CVE-2026-58012)\n\nIt was discovered that GLib's GIOChannel had a buffer over-read when\nusing a custom line terminator. An attacker could use this to cause\ninformation disclosure or a denial of service. (CVE-2026-58013)\n\nIt was discovered that GLib's GKeyFile had an off-by-one error when\nloading a key file with an empty value. An attacker could use this to\ncause an out-of-bounds access or a denial of service. (CVE-2026-58014)\n\nIt was discovered that GLib's DBUS_COOKIE_SHA1 authentication mechanism\nfailed to validate the cookie_context parameter. A malicious D-Bus\nserver could use this to read arbitrary files from the client.\n(CVE-2026-58015)\n\nIt was discovered that GLib's D-Bus introspection XML parser had a\nstate confusion issue. An attacker could use this to cause an\nout-of-bounds read and denial of service. (CVE-2026-58016)","modified":"2026-09-22T03:27:39.276614610Z","published":"2026-09-21T16:25:01Z","related":["UBUNTU-CVE-2026-15588","UBUNTU-CVE-2026-16118","UBUNTU-CVE-2026-58010","UBUNTU-CVE-2026-58011","UBUNTU-CVE-2026-58012","UBUNTU-CVE-2026-58013","UBUNTU-CVE-2026-58014","UBUNTU-CVE-2026-58015","UBUNTU-CVE-2026-58016"],"upstream":["CVE-2026-15588","CVE-2026-16118","CVE-2026-58010","CVE-2026-58011","CVE-2026-58012","CVE-2026-58013","CVE-2026-58014","CVE-2026-58015","CVE-2026-58016","UBUNTU-CVE-2026-15588","UBUNTU-CVE-2026-16118","UBUNTU-CVE-2026-58010","UBUNTU-CVE-2026-58011","UBUNTU-CVE-2026-58012","UBUNTU-CVE-2026-58013","UBUNTU-CVE-2026-58014","UBUNTU-CVE-2026-58015","UBUNTU-CVE-2026-58016"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8794-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-15588"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-16118"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-58010"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-58011"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-58012"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-58013"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-58014"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-58015"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-58016"}],"affected":[{"package":{"name":"glib2.0","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/glib2.0?arch=source&distro=esm-infra-legacy%2Ftrusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.40.2-0ubuntu1.1+esm8"}]}],"versions":["2.38.0-1ubuntu1","2.38.1-1","2.39.1-0ubuntu1","2.39.1-0ubuntu2","2.39.1-0ubuntu3","2.39.2-0ubuntu1","2.39.2-0ubuntu2","2.39.3-0ubuntu4","2.39.4-0ubuntu1","2.39.90-0ubuntu1","2.39.91-0ubuntu2","2.39.91-0ubuntu3","2.39.92-2","2.40.0-1","2.40.0-1ubuntu1","2.40.0-2","2.40.2-0ubuntu1","2.40.2-0ubuntu1.1","2.40.2-0ubuntu1.1+esm1","2.40.2-0ubuntu1.1+esm2","2.40.2-0ubuntu1.1+esm3","2.40.2-0ubuntu1.1+esm4","2.40.2-0ubuntu1.1+esm6","2.40.2-0ubuntu1.1+esm7"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro","binaries":[{"binary_version":"2.40.2-0ubuntu1.1+esm8","binary_name":"libglib2.0-0"},{"binary_name":"libglib2.0-0-refdbg","binary_version":"2.40.2-0ubuntu1.1+esm8"},{"binary_version":"2.40.2-0ubuntu1.1+esm8","binary_name":"libglib2.0-bin"},{"binary_name":"libglib2.0-data","binary_version":"2.40.2-0ubuntu1.1+esm8"},{"binary_version":"2.40.2-0ubuntu1.1+esm8","binary_name":"libglib2.0-tests"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8794-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:14.04:LTS","cves":[{"id":"CVE-2026-15588","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-16118","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-58010","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-58011"},{"id":"CVE-2026-58012","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-58013","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-58014","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-58015"},{"id":"CVE-2026-58016","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"},{"score":"medium","type":"Ubuntu"}]}]}}},{"package":{"name":"glib2.0","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/glib2.0?arch=source&distro=esm-infra-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.48.2-0ubuntu4.8+esm6"}]}],"versions":["2.46.1-1","2.46.1-2","2.47.1-1","2.47.3-3","2.47.4-1","2.47.5-1","2.47.6-1","2.48.0-1ubuntu3","2.48.0-1ubuntu4","2.48.1-1~ubuntu16.04.1","2.48.2-0ubuntu1","2.48.2-0ubuntu3","2.48.2-0ubuntu4","2.48.2-0ubuntu4.1","2.48.2-0ubuntu4.2","2.48.2-0ubuntu4.3","2.48.2-0ubuntu4.4","2.48.2-0ubuntu4.5","2.48.2-0ubuntu4.6","2.48.2-0ubuntu4.7","2.48.2-0ubuntu4.8","2.48.2-0ubuntu4.8+esm1","2.48.2-0ubuntu4.8+esm3","2.48.2-0ubuntu4.8+esm4","2.48.2-0ubuntu4.8+esm5"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro","binaries":[{"binary_name":"libglib2.0-0","binary_version":"2.48.2-0ubuntu4.8+esm6"},{"binary_version":"2.48.2-0ubuntu4.8+esm6","binary_name":"libglib2.0-0-refdbg"},{"binary_name":"libglib2.0-bin","binary_version":"2.48.2-0ubuntu4.8+esm6"},{"binary_name":"libglib2.0-data","binary_version":"2.48.2-0ubuntu4.8+esm6"},{"binary_name":"libglib2.0-tests","binary_version":"2.48.2-0ubuntu4.8+esm6"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8794-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:16.04:LTS","cves":[{"id":"CVE-2026-15588","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-16118","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-58010"},{"id":"CVE-2026-58011","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-58012"},{"id":"CVE-2026-58013","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-58014","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-58015","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-58016","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]}]}}},{"package":{"name":"glib2.0","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/glib2.0?arch=source&distro=esm-infra%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.56.4-0ubuntu0.18.04.9+esm6"}]}],"versions":["2.54.1-1ubuntu1","2.55.2-2ubuntu1","2.56.0-2ubuntu1","2.56.0-4ubuntu1","2.56.1-2ubuntu1","2.56.2-0ubuntu0.18.04.1","2.56.2-0ubuntu0.18.04.2","2.56.3-0ubuntu0.18.04.1","2.56.4-0ubuntu0.18.04.2","2.56.4-0ubuntu0.18.04.3","2.56.4-0ubuntu0.18.04.4","2.56.4-0ubuntu0.18.04.5","2.56.4-0ubuntu0.18.04.6","2.56.4-0ubuntu0.18.04.7","2.56.4-0ubuntu0.18.04.8","2.56.4-0ubuntu0.18.04.9","2.56.4-0ubuntu0.18.04.9+esm3","2.56.4-0ubuntu0.18.04.9+esm4","2.56.4-0ubuntu0.18.04.9+esm5"],"ecosystem_specific":{"binaries":[{"binary_version":"2.56.4-0ubuntu0.18.04.9+esm6","binary_name":"libglib2.0-0"},{"binary_version":"2.56.4-0ubuntu0.18.04.9+esm6","binary_name":"libglib2.0-bin"},{"binary_name":"libglib2.0-data","binary_version":"2.56.4-0ubuntu0.18.04.9+esm6"},{"binary_version":"2.56.4-0ubuntu0.18.04.9+esm6","binary_name":"libglib2.0-dev-bin"},{"binary_name":"libglib2.0-tests","binary_version":"2.56.4-0ubuntu0.18.04.9+esm6"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8794-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[{"id":"CVE-2026-15588","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-16118","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-58010"},{"id":"CVE-2026-58011","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-58012","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-58013","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-58014"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-58015"},{"id":"CVE-2026-58016","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]}]}}},{"package":{"name":"glib2.0","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/glib2.0?arch=source&distro=esm-infra%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.64.6-1~ubuntu20.04.9+esm2"}]}],"versions":["2.62.1-1","2.63.1-2","2.63.1-2ubuntu1","2.63.3-1","2.63.3-3","2.63.5-2","2.64.0-1","2.64.1-1","2.64.2-1~fakesync1","2.64.3-1~ubuntu20.04.1","2.64.6-1~ubuntu20.04.1","2.64.6-1~ubuntu20.04.2","2.64.6-1~ubuntu20.04.3","2.64.6-1~ubuntu20.04.4","2.64.6-1~ubuntu20.04.6","2.64.6-1~ubuntu20.04.7","2.64.6-1~ubuntu20.04.8","2.64.6-1~ubuntu20.04.9","2.64.6-1~ubuntu20.04.9+esm1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro","binaries":[{"binary_name":"libglib2.0-0","binary_version":"2.64.6-1~ubuntu20.04.9+esm2"},{"binary_name":"libglib2.0-bin","binary_version":"2.64.6-1~ubuntu20.04.9+esm2"},{"binary_version":"2.64.6-1~ubuntu20.04.9+esm2","binary_name":"libglib2.0-data"},{"binary_name":"libglib2.0-dev-bin","binary_version":"2.64.6-1~ubuntu20.04.9+esm2"},{"binary_version":"2.64.6-1~ubuntu20.04.9+esm2","binary_name":"libglib2.0-tests"}]},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2026-15588","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-16118","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-58010"},{"id":"CVE-2026-58011","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-58012","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-58013","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-58014","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-58015","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-58016"}],"ecosystem":"Ubuntu:Pro:20.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8794-1.json"}},{"package":{"name":"glib2.0","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/glib2.0?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.72.4-0ubuntu2.10"}]}],"versions":["2.68.4-1ubuntu1","2.70.1-1","2.70.2-1","2.71.0-2","2.71.1-1","2.71.2-1","2.71.3-1","2.72.0-1","2.72.1-1","2.72.4-0ubuntu1","2.72.4-0ubuntu2","2.72.4-0ubuntu2.2","2.72.4-0ubuntu2.3","2.72.4-0ubuntu2.4","2.72.4-0ubuntu2.5","2.72.4-0ubuntu2.6","2.72.4-0ubuntu2.7","2.72.4-0ubuntu2.8","2.72.4-0ubuntu2.9"],"ecosystem_specific":{"binaries":[{"binary_name":"libglib2.0-0","binary_version":"2.72.4-0ubuntu2.10"},{"binary_name":"libglib2.0-bin","binary_version":"2.72.4-0ubuntu2.10"},{"binary_name":"libglib2.0-data","binary_version":"2.72.4-0ubuntu2.10"},{"binary_name":"libglib2.0-dev-bin","binary_version":"2.72.4-0ubuntu2.10"},{"binary_name":"libglib2.0-tests","binary_version":"2.72.4-0ubuntu2.10"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8794-1.json","cves_map":{"cves":[{"id":"CVE-2026-15588","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-16118"},{"id":"CVE-2026-58010","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-58011"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-58012"},{"id":"CVE-2026-58013","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-58014","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-58015","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-58016"}],"ecosystem":"Ubuntu:22.04:LTS"}}},{"package":{"name":"glib2.0","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/glib2.0?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.80.0-6ubuntu3.9"}]}],"versions":["2.78.0-2","2.78.1-4","2.78.3-1","2.78.3-2","2.79.1-1","2.79.2-1~ubuntu1","2.79.3-3ubuntu5","2.80.0-6ubuntu1","2.80.0-6ubuntu3","2.80.0-6ubuntu3.1","2.80.0-6ubuntu3.2","2.80.0-6ubuntu3.4","2.80.0-6ubuntu3.5","2.80.0-6ubuntu3.6","2.80.0-6ubuntu3.7","2.80.0-6ubuntu3.8"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"2.80.0-6ubuntu3.9","binary_name":"gir1.2-girepository-3.0"},{"binary_name":"gir1.2-glib-2.0","binary_version":"2.80.0-6ubuntu3.9"},{"binary_version":"2.80.0-6ubuntu3.9","binary_name":"libgirepository-2.0-0"},{"binary_version":"2.80.0-6ubuntu3.9","binary_name":"libglib2.0-0t64"},{"binary_name":"libglib2.0-bin","binary_version":"2.80.0-6ubuntu3.9"},{"binary_version":"2.80.0-6ubuntu3.9","binary_name":"libglib2.0-data"},{"binary_name":"libglib2.0-dev-bin","binary_version":"2.80.0-6ubuntu3.9"},{"binary_name":"libglib2.0-tests","binary_version":"2.80.0-6ubuntu3.9"}]},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2026-15588","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-16118"},{"id":"CVE-2026-58010","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-58011","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-58012","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-58013","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-58014","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-58015"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-58016"}],"ecosystem":"Ubuntu:24.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8794-1.json"}},{"package":{"name":"glib2.0","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/glib2.0?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.88.0-1ubuntu0.1"}]}],"versions":["2.86.0-2","2.86.1-1","2.86.1-2","2.86.2-1","2.86.3-1","2.86.3-4","2.87.2-2","2.87.2-3","2.87.3-1","2.88.0-1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.88.0-1ubuntu0.1","binary_name":"gir1.2-girepository-3.0"},{"binary_version":"2.88.0-1ubuntu0.1","binary_name":"gir1.2-glib-2.0"},{"binary_name":"girepository-tools","binary_version":"2.88.0-1ubuntu0.1"},{"binary_name":"libgio-2.0-dev-bin","binary_version":"2.88.0-1ubuntu0.1"},{"binary_version":"2.88.0-1ubuntu0.1","binary_name":"libgirepository-2.0-0"},{"binary_name":"libglib2.0-0t64","binary_version":"2.88.0-1ubuntu0.1"},{"binary_name":"libglib2.0-bin","binary_version":"2.88.0-1ubuntu0.1"},{"binary_name":"libglib2.0-data","binary_version":"2.88.0-1ubuntu0.1"},{"binary_name":"libglib2.0-dev-bin","binary_version":"2.88.0-1ubuntu0.1"},{"binary_version":"2.88.0-1ubuntu0.1","binary_name":"libglib2.0-tests"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2026-15588","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-16118","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-58010","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-58011","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-58012"},{"id":"CVE-2026-58013","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-58014","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-58015","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-58016"}],"ecosystem":"Ubuntu:26.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8794-1.json"}}],"schema_version":"1.9.0"}