{"schema_version":"1.7.2","id":"OESA-2026-3725","modified":"2026-09-14T16:33:45Z","published":"2026-09-14T16:33:45Z","upstream":["CVE-2026-16118"],"summary":"glib2 security update","details":"GLib is a bundle of three (formerly five) low-level system libraries written in C and developed mainly by GNOME. GLib&amp;apos;s code was separated from GTK, so it can be used by software other than GNOME and has been developed in parallel ever since.\r\n\r\nSecurity Fix(es):\n\nA flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.(CVE-2026-16118)","affected":[{"package":{"ecosystem":"openEuler:24.03-LTS-SP4","name":"glib2","purl":"pkg:rpm/openEuler/glib2&distro=openEuler-24.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.78.3-19.oe2403sp4"}]}],"ecosystem_specific":{"aarch64":["glib2-2.78.3-19.oe2403sp4.aarch64.rpm","glib2-debuginfo-2.78.3-19.oe2403sp4.aarch64.rpm","glib2-debugsource-2.78.3-19.oe2403sp4.aarch64.rpm","glib2-devel-2.78.3-19.oe2403sp4.aarch64.rpm","glib2-static-2.78.3-19.oe2403sp4.aarch64.rpm","glib2-tests-2.78.3-19.oe2403sp4.aarch64.rpm"],"noarch":["glib2-help-2.78.3-19.oe2403sp4.noarch.rpm"],"src":["glib2-2.78.3-19.oe2403sp4.src.rpm"],"x86_64":["glib2-2.78.3-19.oe2403sp4.x86_64.rpm","glib2-debuginfo-2.78.3-19.oe2403sp4.x86_64.rpm","glib2-debugsource-2.78.3-19.oe2403sp4.x86_64.rpm","glib2-devel-2.78.3-19.oe2403sp4.x86_64.rpm","glib2-static-2.78.3-19.oe2403sp4.x86_64.rpm","glib2-tests-2.78.3-19.oe2403sp4.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3725"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16118"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"}],"database_specific":{"severity":"High"}}
