Red Hat Product Errata RHSA-2026:51182 - Security Advisory Issued: 2026-08-06 Updated: 2026-08-06 RHSA-2026:51182 - Security Advisory Overview Updated Packages Synopsis Important: glib2 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for glib2 is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures. Security Fix(es): glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" (CVE-2026-58016) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2492257 - CVE-2026-58016 glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" CVEs CVE-2026-58016 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 SRPM glib2-2.56.4-165.el8_8.1.src.rpm SHA-256: 52e679a9568352314502be5088d23152467f30c3f3159c5b418304160547af7f x86_64 glib2-2.56.4-165.el8_8.1.i686.rpm SHA-256: d13c1463c0e9d3d18509845253444b074630261d817d73c3d52923ba7012cbbf glib2-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 197b34dc7896b3b11ceaab1da9959b4a2bd794618a0ff83b4183f7334447a652 glib2-debuginfo-2.56.4-165.el8_8.1.i686.rpm SHA-256: bd5ff76b1b935c37b959c85b81d08a8bc85a94c5f69047a4a61e55c264a74bb1 glib2-debuginfo-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 3d77029351a64512e0385d35c64736cd84904fe7dbb7b67680de6d9a7faf50dd glib2-debugsource-2.56.4-165.el8_8.1.i686.rpm SHA-256: 83cc3fda8454ddf7d4ff08ff8b9a02f166748f18d2a443e0bd9108b5a1f19177 glib2-debugsource-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 7fb7901d09225a18d7f587a128f8d1b967fea059d3f59ac2da11dce402c162f1 glib2-devel-2.56.4-165.el8_8.1.i686.rpm SHA-256: 394cdd91a964ee50142474d74b94777e676ea416456700e684d9a80b6888db03 glib2-devel-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 225266c137dd478361f7d658ae05f722461e1fa960c4f7f63f0d961be5ae2066 glib2-devel-debuginfo-2.56.4-165.el8_8.1.i686.rpm SHA-256: 39ab7da9f8239dd13b5e0a62a93b64f769a287f2df7c11d1d8b11ec634558101 glib2-devel-debuginfo-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 5e119fbbba0c98e167359d39e9d392aac57be8d12c2d406324d5f998830d9bd8 glib2-fam-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: e4456f6ef4b1e7d952dd375c59b1c70c140fec3e0f2b21304b5e5deea4ea1ca1 glib2-fam-debuginfo-2.56.4-165.el8_8.1.i686.rpm SHA-256: 77927c99a70b05ca574027e1663bfe8a70c78178ed47616a856648292b213534 glib2-fam-debuginfo-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: f46a376c6c74070937b717968e48ab8f71dd6a1f9a6df0de84f003679d2072ce glib2-tests-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 7c70a62467ccb06442ef1bf39065ab56611b41ee24200e055e6380eb13fcac0d glib2-tests-debuginfo-2.56.4-165.el8_8.1.i686.rpm SHA-256: 8539e7415d47d5e303398924c44a80cd7e24ffe48757c91240efed2043980276 glib2-tests-debuginfo-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 7929f060e4bb5a84693a489be27395197b013a23cf64cff8b2766e7ebd7c6799 Red Hat Enterprise Linux Server - TUS 8.8 SRPM glib2-2.56.4-165.el8_8.1.src.rpm SHA-256: 52e679a9568352314502be5088d23152467f30c3f3159c5b418304160547af7f x86_64 glib2-2.56.4-165.el8_8.1.i686.rpm SHA-256: d13c1463c0e9d3d18509845253444b074630261d817d73c3d52923ba7012cbbf glib2-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 197b34dc7896b3b11ceaab1da9959b4a2bd794618a0ff83b4183f7334447a652 glib2-debuginfo-2.56.4-165.el8_8.1.i686.rpm SHA-256: bd5ff76b1b935c37b959c85b81d08a8bc85a94c5f69047a4a61e55c264a74bb1 glib2-debuginfo-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 3d77029351a64512e0385d35c64736cd84904fe7dbb7b67680de6d9a7faf50dd glib2-debugsource-2.56.4-165.el8_8.1.i686.rpm SHA-256: 83cc3fda8454ddf7d4ff08ff8b9a02f166748f18d2a443e0bd9108b5a1f19177 glib2-debugsource-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 7fb7901d09225a18d7f587a128f8d1b967fea059d3f59ac2da11dce402c162f1 glib2-devel-2.56.4-165.el8_8.1.i686.rpm SHA-256: 394cdd91a964ee50142474d74b94777e676ea416456700e684d9a80b6888db03 glib2-devel-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 225266c137dd478361f7d658ae05f722461e1fa960c4f7f63f0d961be5ae2066 glib2-devel-debuginfo-2.56.4-165.el8_8.1.i686.rpm SHA-256: 39ab7da9f8239dd13b5e0a62a93b64f769a287f2df7c11d1d8b11ec634558101 glib2-devel-debuginfo-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 5e119fbbba0c98e167359d39e9d392aac57be8d12c2d406324d5f998830d9bd8 glib2-fam-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: e4456f6ef4b1e7d952dd375c59b1c70c140fec3e0f2b21304b5e5deea4ea1ca1 glib2-fam-debuginfo-2.56.4-165.el8_8.1.i686.rpm SHA-256: 77927c99a70b05ca574027e1663bfe8a70c78178ed47616a856648292b213534 glib2-fam-debuginfo-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: f46a376c6c74070937b717968e48ab8f71dd6a1f9a6df0de84f003679d2072ce glib2-tests-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 7c70a62467ccb06442ef1bf39065ab56611b41ee24200e055e6380eb13fcac0d glib2-tests-debuginfo-2.56.4-165.el8_8.1.i686.rpm SHA-256: 8539e7415d47d5e303398924c44a80cd7e24ffe48757c91240efed2043980276 glib2-tests-debuginfo-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 7929f060e4bb5a84693a489be27395197b013a23cf64cff8b2766e7ebd7c6799 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 SRPM glib2-2.56.4-165.el8_8.1.src.rpm SHA-256: 52e679a9568352314502be5088d23152467f30c3f3159c5b418304160547af7f ppc64le glib2-2.56.4-165.el8_8.1.ppc64le.rpm SHA-256: 9d11b3f3865bb9fa36007543bca16ba6c36d202a9bab0edafd775a15aa748f36 glib2-debuginfo-2.56.4-165.el8_8.1.ppc64le.rpm SHA-256: d266df64c71ad0e9af382e5fb822c8a119d92a75d1ec0f4fcfa69b9607fbe0c0 glib2-debugsource-2.56.4-165.el8_8.1.ppc64le.rpm SHA-256: b2e09987d1aa33f34b318eb4135675176ef3414e0610438bc6b7e32e9ffa9e6b glib2-devel-2.56.4-165.el8_8.1.ppc64le.rpm SHA-256: 7cd5f46f2c7434f173b4647e8a947c82e4681221e9e17c85116cd310982115fb glib2-devel-debuginfo-2.56.4-165.el8_8.1.ppc64le.rpm SHA-256: 02721f49bdd5972b9e686c7a3581a6915b7cfbfb165d06289583d2ae1ca17de4 glib2-fam-2.56.4-165.el8_8.1.ppc64le.rpm SHA-256: 933f0a9d43592453cafd3a478d53e4c6e0f2809bf8c9955bf144d396e53d1561 glib2-fam-debuginfo-2.56.4-165.el8_8.1.ppc64le.rpm SHA-256: 196c6308ab7da66e00f305d0b1835cee25a532ab516b4142667865ad05e9bd57 glib2-tests-2.56.4-165.el8_8.1.ppc64le.rpm SHA-256: 73a4cc7c72b03a91373f8737fa0a93601fe535a39104efac9f77bb084353b55f glib2-tests-debuginfo-2.56.4-165.el8_8.1.ppc64le.rpm SHA-256: a1af697f42ed0ab9a8464aadfe76177cf0da8df30d8bc32661232aa5f3b73ca7 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 SRPM glib2-2.56.4-165.el8_8.1.src.rpm SHA-256: 52e679a9568352314502be5088d23152467f30c3f3159c5b418304160547af7f x86_64 glib2-2.56.4-165.el8_8.1.i686.rpm SHA-256: d13c1463c0e9d3d18509845253444b074630261d817d73c3d52923ba7012cbbf glib2-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 197b34dc7896b3b11ceaab1da9959b4a2bd794618a0ff83b4183f7334447a652 glib2-debuginfo-2.56.4-165.el8_8.1.i686.rpm SHA-256: bd5ff76b1b935c37b959c85b81d08a8bc85a94c5f69047a4a61e55c264a74bb1 glib2-debuginfo-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 3d77029351a64512e0385d35c64736cd84904fe7dbb7b67680de6d9a7faf50dd glib2-debugsource-2.56.4-165.el8_8.1.i686.rpm SHA-256: 83cc3fda8454ddf7d4ff08ff8b9a02f166748f18d2a443e0bd9108b5a1f19177 glib2-debugsource-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 7fb7901d09225a18d7f587a128f8d1b967fea059d3f59ac2da11dce402c162f1 glib2-devel-2.56.4-165.el8_8.1.i686.rpm SHA-256: 394cdd91a964ee50142474d74b94777e676ea416456700e684d9a80b6888db03 glib2-devel-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 225266c137dd478361f7d658ae05f722461e1fa960c4f7f63f0d961be5ae2066 glib2-devel-debuginfo-2.56.4-165.el8_8.1.i686.rpm SHA-256: 39ab7da9f8239dd13b5e0a62a93b64f769a287f2df7c11d1d8b11ec634558101 glib2-devel-debuginfo-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 5e119fbbba0c98e167359d39e9d392aac57be8d12c2d406324d5f998830d9bd8 glib2-fam-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: e4456f6ef4b1e7d952dd375c59b1c70c140fec3e0f2b21304b5e5deea4ea1ca1 glib2-fam-debuginfo-2.56.4-165.el8_8.1.i686.rpm SHA-256: 77927c99a70b05ca574027e1663bfe8a70c78178ed47616a856648292b213534 glib2-fam-debuginfo-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: f46a376c6c74070937b717968e48ab8f71dd6a1f9a6df0de84f003679d2072ce glib2-tests-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 7c70a62467ccb06442ef1bf39065ab56611b41ee24200e055e6380eb13fcac0d glib2-tests-debuginfo-2.56.4-165.el8_8.1.i686.rpm SHA-256: 8539e7415d47d5e303398924c44a80cd7e24ffe48757c91240efed2043980276 glib2-tests-debuginfo-2.56.4-165.el8_8.1.x86_64.rpm SHA-256: 7929f060e4bb5a84693a489be27395197b013a23cf64cff8b2766e7ebd7c6799 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
An integer underflow vulnerability (CVE-2026-58016, CVSS 7.5 HIGH) exists in glib2's `g_dbus_node_info_new_for_xml` function, which could be exploited via malicious D-Bus introspection XML. The vulnerability affects glib2 versions prior to 2.88.1, including packages shipped with Red Hat Enterprise Linux versions 6.0, 7.0, 8.0, and 9.0. Red Hat has released updated packages for specific RHEL 8.8 streams; users should apply the provided patches to remediate.