Beveiligingsadvies

CVE-2026-58015

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-30 13:02:45
Laatst bijgewerkt 2026-09-09 07:46:09
Toegewezen door redhat
CVSS-score 5.9
Status PUBLISHED

Beschrijving

A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.