[El-errata] ELSA-2026-49512 Important: Oracle Linux 8 mingw-glib2 security update
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Wed Aug 5 21:40:57 UTC 2026
Oracle Linux Security Advisory ELSA-2026-49512
http://linux.oracle.com/errata/ELSA-2026-49512.html
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
x86_64:
mingw32-glib2-2.70.1-9.el8_10.noarch.rpm
mingw32-glib2-static-2.70.1-9.el8_10.noarch.rpm
mingw64-glib2-2.70.1-9.el8_10.noarch.rpm
mingw64-glib2-static-2.70.1-9.el8_10.noarch.rpm
SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates/mingw-glib2-2.70.1-9.el8_10.src.rpm
Related CVEs:
CVE-2025-14087
CVE-2026-58010
CVE-2026-58011
CVE-2026-58012
CVE-2026-58013
CVE-2026-58014
CVE-2026-58015
CVE-2026-58016
Description of changes:
[2.70.1-9]
- Fix CVE-2026-58010: off-by-one error in gvs_tuple_is_normal()
Resolves: RHEL-212164
[2.70.1-8]
- Fix CVE-2026-58011: g_date_time_add_full() range validation
Resolves: RHEL-212184
[2.70.1-7]
- Fix CVE-2026-58013: memcmp buffer over-read in giochannel
Resolves: RHEL-212234
[2.70.1-6]
- Fix CVE-2026-58012: buffer overflow in gregex substitutions
Resolves: RHEL-212200
[2.70.1-5]
- Fix CVE-2025-14087: integer overflow in GVariant parser
Resolves: RHEL-154707
[2.70.1-4]
- Fix CVE-2026-58016: D-Bus introspection XML node nesting check
Resolves: RHEL-190617
[2.70.1-3]
- Fix CVE-2026-58014: one-byte heap under-read in mingw-glib2
Resolves: RHEL-190609
[2.70.1-2]
- Fix CVE-2026-58015: D-Bus cookie context path traversal
Resolves: RHEL-212246
More information about the El-errata
mailing list