CVE-2026-58015: Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive

Published Jun 24, 2026
·
Updated

A flaw was found in GLib. The D-Bus client-side implementation of the DBUSCOOKIESHA1 SASL authentication mechanism does not validate the cookiecontext parameter received from the server. A malicious D-Bus server can supply a cookiecontext containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.

Other sources

Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyringlookupentry and mechanismclientdatareceive

Microsoft

The GLib D-Bus client-side implementation of the DBUSCOOKIESHA1 SASL authentication mechanism does not validate the cookiecontext parameter received from the server. The D-Bus specification explicitly states that cookie context names must not contain the characters /, \, . (period), spaces, or ASCII control characters. However, GLib's client-side code accepts this value verbatim and uses it to construct a filesystem path via gbuildfilename(). A malicious D-Bus server can supply a cookiecontext containing path traversal sequences such as ../.targetfile, causing the client to read an arbitrary file outside the ~/.dbus-keyrings/ directory. The file contents (specifically the third space-separated token of the first matching line) are then incorporated into a SHA1 hash computation and sent back to the server as part of the authentication response. The server can verify guessed file contents against this SHA1 hash, enabling data exfiltration.

Red Hat

Affected Software

8 affected componentsFixes available
GLib glib
Gnome GLib<2.88.1
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Enterprise Linux=10.0
Microsoft azl3 glib 2.78.6-9<2.78.6-10
2.78.6-10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 2.78.6-10

Event History

Jun 24, 2026
Data Sourced
via Red Hat·05:28 PM
DescriptionSeverityAffected Software
Jun 30, 2026
CVE Published
via MITRE·01:02 PM
Data Sourced
via MITRE·01:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:19 PM
DescriptionSeverityWeaknessAffected Software
Jul 1, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-58015?

The severity of CVE-2026-58015 is classified as high with a score of 7.5.

2

What impact does CVE-2026-58015 have?

CVE-2026-58015 can allow a malicious D-Bus server to exploit the client through path traversal sequences.

3

How do I fix CVE-2026-58015?

To mitigate CVE-2026-58015, ensure that you update GLib to the latest version that addresses this vulnerability.

4

Which systems are affected by CVE-2026-58015?

CVE-2026-58015 affects GLib and is particularly relevant for users of Red Hat Enterprise Linux and GNOME.

5

How does CVE-2026-58015 affect D-Bus authentication?

CVE-2026-58015 affects the D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism by not properly validating the cookie_context parameter.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203