Description
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.
Published: 2026-07-20
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8794-1 GLib vulnerabilities
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:39985 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:40485 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:42329 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:55440 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:57015 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:58981 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:61766 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:61783 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:63135 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:63138 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:63140 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:65762 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:65763 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:65767 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:65768 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:65769 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:65770 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:65771 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:65773 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:66018 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:72394 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:72395 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:72399 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:72470 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:72475 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:72476 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:72502 cve-icon cve-icon
https://access.redhat.com/security/cve/CVE-2026-15588 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2499675 cve-icon cve-icon
https://gitlab.gnome.org/GNOME/glib/-/issues/3985 cve-icon cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-15588 cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-15588 cve-icon
History

Tue, 29 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
References

Mon, 28 Sep 2026 14:30:00 +0000


Mon, 28 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
References

Mon, 28 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:cert_manager:1.20::el9
References

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
References

Wed, 09 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat enterprise Linux Eus
Redhat rhel Eus
Redhat rhel Tus
CPEs cpe:/a:redhat:rhel_eus:9.6::appstream
cpe:/a:redhat:rhel_eus:9.6::crb
cpe:/o:redhat:enterprise_linux_eus:10.0
cpe:/o:redhat:rhel_aus:8.6::baseos
cpe:/o:redhat:rhel_e4s:8.8::baseos
cpe:/o:redhat:rhel_eus:9.6::baseos
cpe:/o:redhat:rhel_eus_long_life:8.6::baseos
cpe:/o:redhat:rhel_tus:8.8::baseos
Vendors & Products Redhat enterprise Linux Eus
Redhat rhel Eus
Redhat rhel Tus
References

Wed, 09 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel E4s
Redhat rhel Els
CPEs cpe:/o:redhat:enterprise_linux:7 cpe:/a:redhat:rhel_e4s:9.2::appstream
cpe:/a:redhat:rhel_e4s:9.4::appstream
cpe:/o:redhat:rhel_e4s:9.2::baseos
cpe:/o:redhat:rhel_e4s:9.4::baseos
cpe:/o:redhat:rhel_els:7
Vendors & Products Redhat rhel E4s
Redhat rhel Els
References

Wed, 09 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Aus
Redhat rhel Eus Long Life
CPEs cpe:/o:redhat:rhel_aus:8.4::baseos
cpe:/o:redhat:rhel_eus_long_life:8.4::baseos
Vendors & Products Redhat rhel Aus
Redhat rhel Eus Long Life
References

Tue, 08 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat cert Manager
CPEs cpe:/a:redhat:cert_manager:1.19::el9
Vendors & Products Redhat cert Manager
References

Tue, 01 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat discovery
CPEs cpe:/a:redhat:discovery:2::el9
Vendors & Products Redhat discovery
References

Mon, 31 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:8::crb
cpe:/o:redhat:enterprise_linux:8::baseos
References

Tue, 25 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhui
CPEs cpe:/a:redhat:rhui:5::el9
Vendors & Products Redhat rhui
References

Wed, 19 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:10.2
References

Mon, 17 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:9::appstream
cpe:/a:redhat:enterprise_linux:9::crb
cpe:/o:redhat:enterprise_linux:9::baseos
References

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat hardened Images
Redhat openshift Container Platform
Vendors & Products Redhat hardened Images
Redhat openshift Container Platform

Tue, 21 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
References

Tue, 21 Jul 2026 10:15:00 +0000


Tue, 21 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 20 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.
Title Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering
First Time appeared Redhat
Redhat enterprise Linux
Redhat hummingbird
Redhat openshift
Weaknesses CWE-770
CPEs cpe:/a:redhat:hummingbird:1
cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat hummingbird
Redhat openshift
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Redhat Cert Manager Discovery Enterprise Linux Enterprise Linux Eus Hardened Images Hummingbird Openshift Openshift Container Platform Rhel Aus Rhel E4s Rhel Els Rhel Eus Rhel Eus Long Life Rhel Tus Rhui
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-29T00:21:20.518Z

Reserved: 2026-07-13T13:21:08.322Z

Link: CVE-2026-15588

cve-icon Vulnrichment

Updated: 2026-07-20T13:49:53.438Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-20T12:17:55.220

Modified: 2026-09-29T01:16:45.597

Link: CVE-2026-15588

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-12T10:10:00Z

Links: CVE-2026-15588 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:35:49Z

Weaknesses