Red Hat xdgmime: heap buffer overflow
High7.1CVE-2026-16118 · Published Jul 17, 2026 · updated Sep 24, 2026
A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| xdgmime Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-122
- www.cve.org/CVERecord?id=CVE-2026-16118
- nvd.nist.gov/vuln/detail/CVE-2026-16118
- access.redhat.com/errata/RHSA-2026:64799
- access.redhat.com/errata/RHSA-2026:64800
- access.redhat.com/errata/RHSA-2026:66451
- access.redhat.com/errata/RHSA-2026:67956
- access.redhat.com/errata/RHSA-2026:70636
- access.redhat.com/errata/RHSA-2026:71403
- access.redhat.com/errata/RHSA-2026:71404
- access.redhat.com/errata/RHSA-2026:71405
- access.redhat.com/security/cve/CVE-2026-16118
- bugzilla.redhat.com/show_bug.cgi?id=2501732
- gitlab.freedesktop.org/xdg/xdgmime/-/work_items/41
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 17 | Red Hat Data Grid 8: untrusted input in a security decision | Medium5.4 | No fix yet |
| Jul 17 | Red Hat keycloak-services: attacker could obtain access | Medium4.3 | No fix yet |
| Jul 17 | Red Hat Data Grid 8: weakly protected credentials | Medium4.3 | No fix yet |
| Jul 17 | Red Hat admin REST API of Keycloak: missing authorization | Medium4.9 | No fix yet |
| Jul 17 | Red Hat default-groups REST endpoint: information disclosure | Medium4.3 | No fix yet |
| Jul 17 | Red Hat keycloak-services: session fixation | Medium5.4 | No fix yet |