CVE-2026-58015

⚪ Do wiadomości

Błąd w GLib pozwala złośliwemu serwerowi D-Bus na wyciek wrażliwych danych przez przejście do plików.

CVSS
5.9
EPSS
0.9%
Exploit
poc
Vendor
redhat
Opis źródłowy (NVD)

A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.

exploit path-traversal Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.9
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.9%
Opublikowano (NVD)2026-06-30 13:19:17 UTC
Ostatnia modyfikacja (NVD)2026-10-02 03:16:49 UTC
Referencje