[El-errata] ELSA-2026-57015 Moderate: Oracle Linux 10 glib2 security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Thu Aug 20 10:25:52 UTC 2026


Oracle Linux Security Advisory ELSA-2026-57015

http://linux.oracle.com/errata/ELSA-2026-57015.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
glib2-2.80.4-12.el10_2.21.x86_64.rpm
glib2-devel-2.80.4-12.el10_2.21.x86_64.rpm
glib2-doc-2.80.4-12.el10_2.21.x86_64.rpm
glib2-static-2.80.4-12.el10_2.21.x86_64.rpm
glib2-tests-2.80.4-12.el10_2.21.x86_64.rpm

aarch64:
glib2-2.80.4-12.el10_2.21.aarch64.rpm
glib2-devel-2.80.4-12.el10_2.21.aarch64.rpm
glib2-doc-2.80.4-12.el10_2.21.aarch64.rpm
glib2-static-2.80.4-12.el10_2.21.aarch64.rpm
glib2-tests-2.80.4-12.el10_2.21.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/glib2-2.80.4-12.el10_2.21.src.rpm

Related CVEs:

CVE-2026-15588
CVE-2026-58010
CVE-2026-58011
CVE-2026-58012
CVE-2026-58013
CVE-2026-58014
CVE-2026-58015




Description of changes:

[2.80.4-21]
- Fix CVE-2026-15588: limit D-Bus auth line read length

[2.80.4-20]
- Fix CVE-2026-58011: range validation in g_date_time_add_full()

[2.80.4-19]
- Fix CVE-2026-58012: buffer overflow in gregex.c with G_REGEX_RAW

[2.80.4-18]
- Fix CVE-2026-58010: off-by-one in GVariant tuple offset checking

[2.80.4-17]
- Fix CVE-2026-58015: validate D-Bus DBUS_COOKIE_SHA1 cookie context

[2.80.4-16]
- Fix CVE-2026-58014: heap under-read in g_key_file_get_locale_string_list

[2.80.4-15]
- Fix CVE-2026-58013: GIOChannel memcmp buffer over-read

[2.80.4-14]
- Fix CVE-2026-58016: D-Bus introspection XML node nesting validation

[2.80.4-13]
- Fix CVE-2025-14087 and CVE-2025-14512




More information about the El-errata mailing list