[El-errata] ELSA-2026-55440 Moderate: Oracle Linux 9 glib2 security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Thu Aug 20 10:25:15 UTC 2026


Oracle Linux Security Advisory ELSA-2026-55440

http://linux.oracle.com/errata/ELSA-2026-55440.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
glib2-2.68.4-19.el9_8.9.i686.rpm
glib2-2.68.4-19.el9_8.9.x86_64.rpm
glib2-devel-2.68.4-19.el9_8.9.i686.rpm
glib2-devel-2.68.4-19.el9_8.9.x86_64.rpm
glib2-doc-2.68.4-19.el9_8.9.noarch.rpm
glib2-static-2.68.4-19.el9_8.9.i686.rpm
glib2-static-2.68.4-19.el9_8.9.x86_64.rpm
glib2-tests-2.68.4-19.el9_8.9.x86_64.rpm

aarch64:
glib2-2.68.4-19.el9_8.9.aarch64.rpm
glib2-devel-2.68.4-19.el9_8.9.aarch64.rpm
glib2-doc-2.68.4-19.el9_8.9.noarch.rpm
glib2-static-2.68.4-19.el9_8.9.aarch64.rpm
glib2-tests-2.68.4-19.el9_8.9.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/glib2-2.68.4-19.el9_8.9.src.rpm

Related CVEs:

CVE-2026-15588
CVE-2026-58010
CVE-2026-58011
CVE-2026-58012
CVE-2026-58013
CVE-2026-58014
CVE-2026-58015




Description of changes:

[2.68.4-19.9]
- Fix CVE-2026-15588: limit D-Bus auth line read length

[2.68.4-19.8]
- Fix CVE-2026-58010: off-by-one in GVariant tuple offset checking
- Resolves: RHEL-212157

[2.68.4-19.7]
- Fix CVE-2026-58012: buffer overflow in gregex.c with G_REGEX_RAW
- Resolves: RHEL-212217

[2.68.4-19.6]
- Fix CVE-2026-58011: range validation in g_date_time_add_full()
- Resolves: RHEL-212194

[2.68.4-19.5]
- Fix CVE-2026-58013: buffer over-read in GIOChannel with long terminators
- Resolves: RHEL-212236

[2.68.4-19.4]
- Fix CVE-2026-58014: heap under-read in g_key_file_get_locale_string_list
- Resolves: RHEL-190589

[2.68.4-19.3]
- Fix CVE-2026-58015: validate D-Bus DBUS_COOKIE_SHA1 cookie context
- Resolves: RHEL-212261




More information about the El-errata mailing list