Bug 2499675 (CVE-2026-15588)

Summary: CVE-2026-15588 GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: akhatavk, aos-team-art-private, asdas, dpaolell, jdelft, jupierce, lgarciaa, mbiarnes, ppalepu, ppostler, prdhamdh, rhel-process-autobot, sghai, sidsharm, suppawar, vlaad, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2500599, 2500600, 2500601, 2500602    
Bug Blocks:    

Description OSIDB Bzimport 2026-07-13 13:51:10 UTC
A `GDBus` authentication denial-of-service / resource exhaustion flaw has been reported. The vulnerability involves a lack of line length limitations when `gdbusauth` reads input from a client. This can be exploited by an unauthenticated remote or local attacker to cause excessive memory and CPU consumption.

Comment 2 errata-xmlrpc 2026-08-17 05:48:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:55440 https://access.redhat.com/errata/RHSA-2026:55440

Comment 3 errata-xmlrpc 2026-08-19 16:42:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:57015 https://access.redhat.com/errata/RHSA-2026:57015

Comment 4 errata-xmlrpc 2026-08-31 19:29:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:61766 https://access.redhat.com/errata/RHSA-2026:61766

Comment 5 errata-xmlrpc 2026-09-09 02:27:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:65762 https://access.redhat.com/errata/RHSA-2026:65762

Comment 6 errata-xmlrpc 2026-09-09 02:59:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:65771 https://access.redhat.com/errata/RHSA-2026:65771

Comment 7 errata-xmlrpc 2026-09-09 02:59:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:65767 https://access.redhat.com/errata/RHSA-2026:65767

Comment 8 errata-xmlrpc 2026-09-09 03:04:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:65769 https://access.redhat.com/errata/RHSA-2026:65769

Comment 9 errata-xmlrpc 2026-09-09 03:09:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:65763 https://access.redhat.com/errata/RHSA-2026:65763

Comment 10 errata-xmlrpc 2026-09-09 03:15:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:65773 https://access.redhat.com/errata/RHSA-2026:65773

Comment 11 errata-xmlrpc 2026-09-09 03:27:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:65768 https://access.redhat.com/errata/RHSA-2026:65768

Comment 12 errata-xmlrpc 2026-09-09 03:28:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:65770 https://access.redhat.com/errata/RHSA-2026:65770