Bug 2500599 - CVE-2026-15588 glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering [fedora-all]
Summary: CVE-2026-15588 glib2: GDBusServer pre-authentication DoS via unbounded SASL l...
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: glib2
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Matthias Clasen
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["8c9573cd-0a4e-46e9-aabb-1...
: 2500601 (view as bug list)
Depends On:
Blocks: CVE-2026-15588
TreeView+ depends on / blocked
 
Reported: 2026-07-14 20:14 UTC by Ganesh
Modified: 2026-08-26 00:57 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-08-12 16:44:50 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ganesh 2026-07-14 20:14:36 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A `GDBus` authentication denial-of-service / resource exhaustion flaw has been reported. The vulnerability involves a lack of line length limitations when `gdbusauth` reads input from a client. This can be exploited by an unauthenticated remote or local attacker to cause excessive memory and CPU consumption.

Comment 1 lpavan 2026-08-12 16:34:21 UTC
This was fixed upstream in 2.88.3 and 2.89.2.

Fedora 45 and 44 are not affected (glib 2.89.3 and 2.88.3 respectively). Although Fedora 43 is affected (glib 2.86.5), the CVE is considered low impact in practice. Furthermore, Fedora 43 will EOL on December 9, so no fix is planned.

Comment 2 Adrian Vovk 2026-08-26 00:57:02 UTC
*** Bug 2500601 has been marked as a duplicate of this bug. ***


Note You need to log in before you can comment on or make changes to this bug.