[CLSA-2026:1789392191] glib2: Fix of CVE-2026-16118
Type:
security
Severity:
Important
Release date:
2026-09-14 13:23:23 UTC
Description:
- CVE-2026-16118: fix a 2-byte out-of-bounds write in the little-endian byte-swap of _xdg_mime_magic_parse_magic_line() by parenthesizing (ptr + i) before the cast, so the write side uses byte offsets instead of scaling by the word size
CVEs fixed:
Updated packages:
  • glib2-2.56.4-163.el8.tuxcare.els8.i686.rpm
    sha:0787a1cfae137d99c483d1fe5ca88143aad6af34ad3978ec03023c0425951514
  • glib2-2.56.4-163.el8.tuxcare.els8.x86_64.rpm
    sha:89f338f578a226af09dc1dbb7b0706732da9d568483c96d847fe6f3cd60601f4
  • glib2-devel-2.56.4-163.el8.tuxcare.els8.i686.rpm
    sha:169191c5bd73fdf268cba233895d42258bed0191acad1493a63a9db5b405086d
  • glib2-devel-2.56.4-163.el8.tuxcare.els8.x86_64.rpm
    sha:66ac47a07b46de6286417fa0158ce41969637e104c2c40a5e9f4110a6d857ae5
  • glib2-doc-2.56.4-163.el8.tuxcare.els8.noarch.rpm
    sha:9d5dc0a5da691715f27deb92ab3f47e89094cefbf6dc93027a4e743d0c98ce5a
  • glib2-fam-2.56.4-163.el8.tuxcare.els8.x86_64.rpm
    sha:9fc07be4af8ed2a5a311974a512ed525dbc47bc25c46692efaf06496377e591f
  • glib2-static-2.56.4-163.el8.tuxcare.els8.i686.rpm
    sha:f17d1910c9ef7cca46014c2acce25eb71ab283e37ab861db7e8b30aa1ef0dba6
  • glib2-static-2.56.4-163.el8.tuxcare.els8.x86_64.rpm
    sha:7a994d9c415eed0ce8202d531acff345f5856c2a13196a3553f7b751aed831c4
  • glib2-tests-2.56.4-163.el8.tuxcare.els8.x86_64.rpm
    sha:6330ed0f8fb453ccef85dd78f9f60863b2d68008e9309f22f4b57e46e33f41af
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.