A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-06-30 13:19
Updated : 2026-09-15 12:17
NVD link : CVE-2026-58015
Mitre link : CVE-2026-58015
CVE.ORG link : CVE-2026-58015
JSON object : View
Products Affected
redhat
- enterprise_linux
gnome
- glib
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
NVD-CWE-noinfo