Red HatCVE-2026-15588
Red Hat: denial of service
Medium5.3CVE-2026-15588 · Published Jul 20, 2026 · updated Sep 10, 2026
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-770
- www.cve.org/CVERecord?id=CVE-2026-15588
- nvd.nist.gov/vuln/detail/CVE-2026-15588
- access.redhat.com/errata/RHSA-2026:39985
- access.redhat.com/errata/RHSA-2026:40485
- access.redhat.com/errata/RHSA-2026:42329
- access.redhat.com/errata/RHSA-2026:55440
- access.redhat.com/errata/RHSA-2026:57015
- access.redhat.com/errata/RHSA-2026:58981
- access.redhat.com/errata/RHSA-2026:61766
- access.redhat.com/errata/RHSA-2026:61783
- access.redhat.com/errata/RHSA-2026:63135
- access.redhat.com/errata/RHSA-2026:63138
- access.redhat.com/errata/RHSA-2026:63140
- access.redhat.com/errata/RHSA-2026:65762
- access.redhat.com/errata/RHSA-2026:65763
- access.redhat.com/errata/RHSA-2026:65767
- access.redhat.com/errata/RHSA-2026:65768
- access.redhat.com/errata/RHSA-2026:65769
- access.redhat.com/errata/RHSA-2026:65770
- access.redhat.com/errata/RHSA-2026:65771
- access.redhat.com/errata/RHSA-2026:65773
- access.redhat.com/errata/RHSA-2026:66018
- access.redhat.com/security/cve/CVE-2026-15588
- bugzilla.redhat.com/show_bug.cgi?id=2499675
- gitlab.gnome.org/GNOME/glib/-/issues/3985
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 20 | Red Hat libcupsfilters: denial of service | High7.5 | No fix yet |
| Jul 20 | Red Hat Enterprise Linux 10: stack buffer overflow | Medium6.5 | No fix yet |
| Jul 20 | Red Hat: path traversal | Critical9.0 | No fix yet |
| Jul 20 | Red Hat Enterprise Linux 10: race condition | High7.3 | No fix yet |
| Jul 20 | Red Hat claircore: denial of service | Medium4.3 | No fix yet |
| Jul 20 | Red Hat Enterprise Linux 10: out-of-bounds write | Medium6.5 | No fix yet |