[El-errata] ELSA-2026-49512 Important: Oracle Linux 8 mingw-glib2 security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Wed Aug 5 21:40:57 UTC 2026


Oracle Linux Security Advisory ELSA-2026-49512

http://linux.oracle.com/errata/ELSA-2026-49512.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
mingw32-glib2-2.70.1-9.el8_10.noarch.rpm
mingw32-glib2-static-2.70.1-9.el8_10.noarch.rpm
mingw64-glib2-2.70.1-9.el8_10.noarch.rpm
mingw64-glib2-static-2.70.1-9.el8_10.noarch.rpm



SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/mingw-glib2-2.70.1-9.el8_10.src.rpm

Related CVEs:

CVE-2025-14087
CVE-2026-58010
CVE-2026-58011
CVE-2026-58012
CVE-2026-58013
CVE-2026-58014
CVE-2026-58015
CVE-2026-58016




Description of changes:

[2.70.1-9]
- Fix CVE-2026-58010: off-by-one error in gvs_tuple_is_normal()
  Resolves: RHEL-212164

[2.70.1-8]
- Fix CVE-2026-58011: g_date_time_add_full() range validation
  Resolves: RHEL-212184

[2.70.1-7]
- Fix CVE-2026-58013: memcmp buffer over-read in giochannel
  Resolves: RHEL-212234

[2.70.1-6]
- Fix CVE-2026-58012: buffer overflow in gregex substitutions
  Resolves: RHEL-212200

[2.70.1-5]
- Fix CVE-2025-14087: integer overflow in GVariant parser
  Resolves: RHEL-154707

[2.70.1-4]
- Fix CVE-2026-58016: D-Bus introspection XML node nesting check
  Resolves: RHEL-190617

[2.70.1-3]
- Fix CVE-2026-58014: one-byte heap under-read in mingw-glib2
  Resolves: RHEL-190609

[2.70.1-2]
- Fix CVE-2026-58015: D-Bus cookie context path traversal
  Resolves: RHEL-212246




More information about the El-errata mailing list