CVE-2026-58014
Red Hat Security Advisory: Red Hat Update Infrastructure 5.3 Technology Preview security update
Description
A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.
Metrics
Weakness classes (CWE)
CWE-193Base
Off-by-one Error
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-10 18:18 UTC· secalert@redhat.com
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/58xxx/CVE-2026-58014.json">CVE-2026-58014</a>
- Reference: https://access.redhat.com/errata/RHSA-2026:66018
- CVE Modified2026-09-09 08:17 UTC· secalert@redhat.com
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/58xxx/CVE-2026-58014.json">CVE-2026-58014</a>
- Reference: https://access.redhat.com/errata/RHSA-2026:65763
- Reference: https://access.redhat.com/errata/RHSA-2026:65767
- Reference: https://access.redhat.com/errata/RHSA-2026:65769
- CVE Modified2026-09-09 05:17 UTC· secalert@redhat.com
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/58xxx/CVE-2026-58014.json">CVE-2026-58014</a>
- Reference: https://access.redhat.com/errata/RHSA-2026:65768
- Reference: https://access.redhat.com/errata/RHSA-2026:65770
- Reference: https://access.redhat.com/errata/RHSA-2026:65773
- CVE Modified2026-09-09 03:17 UTC· secalert@redhat.com
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/58xxx/CVE-2026-58014.json">CVE-2026-58014</a>
- Reference: https://access.redhat.com/errata/RHSA-2026:65762
- CVE Modified2026-09-08 23:17 UTC· secalert@redhat.com
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/58xxx/CVE-2026-58014.json">CVE-2026-58014</a>
- Reference: https://access.redhat.com/errata/RHSA-2026:63135
- Reference: https://access.redhat.com/errata/RHSA-2026:63138
- Reference: https://access.redhat.com/errata/RHSA-2026:63140
Affected operating systems
linux
ubuntu / coreutilsjammy
linux
ubuntu / coreutilsnoble
linux
ubuntu / coreutilsresolute
linux
debian / debian_linux11.0
linux
redhat / enterprise_linux10.0
linux
redhat / enterprise_linux10.2
linux
redhat / enterprise_linux6.0
linux
redhat / enterprise_linux7.0
linux
redhat / enterprise_linux8.0
linux
redhat / enterprise_linux9.0
linux
redhat / enterprise_linux9.8
linux
redhat / enterprise_linux_for_els10.2
linux
redhat / enterprise_linux_for_els8.10
linux
redhat / enterprise_linux_for_els9.8
linux
redhat / enterprise_linux_for_eus10.2
linux
redhat / enterprise_linux_for_eus9.8
linux
redhat / enterprise_linux_for_ibm_z_systems10.2
linux
redhat / enterprise_linux_for_ibm_z_systems8.0_s390x
linux
redhat / enterprise_linux_for_ibm_z_systems9.0_s390x
linux
redhat / enterprise_linux_for_ibm_z_systems_els10.2
linux
redhat / enterprise_linux_for_ibm_z_systems_els8.10
linux
redhat / enterprise_linux_for_ibm_z_systems_els9.8
linux
redhat / enterprise_linux_for_ibm_z_systems_eus10.2
linux
redhat / enterprise_linux_for_ibm_z_systems_eus9.8
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
Apple
iOS18.7.10
Apple
iOS26.6.1
Apple
iPadOS18.7.10
Apple
iPadOS26.6.1
Apple
macOSTahoe 26.6.2
bitnami
jre1.9.0
bitnami
nginx-gateway0.1.17
bitnami
nginx-gateway-fabric1.3.0
bitnami
postgresql15.0.0
bitnami
postgresql16.0.0
bitnami
postgresql17.0.0
bitnami
postgresql18.0.0
bitnami
python-min3.10.0
bitnami
python-min3.11.0
bitnami
python-min3.12.0
bitnami
python-min3.13.0
bitnami
python-min3.14.0
f5
dos4.3.0 – 4.7.0
f5
dos
f5
nginx_gateway_fabric1.3.0 – 1.6.2
f5
nginx_gateway_fabric2.0.0 – 2.5.1
f5
nginx_ingress_controller3.5.0 – 3.7.2
f5
nginx_ingress_controller4.0.0 – 4.0.1
f5
nginx_ingress_controller5.0.0 – 5.4.1
References & sources
- https://gitlab.gnome.org/GNOME/libxml2/-/issues/720
- https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.12.7
- https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.11.8
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/INKSSLW5VMZIXHRPZBAW4TJUX5SQKARG/vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VRDJCNQP32LV56KESUQ5SNZKAJWSZZRI/vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5HVUXKYTBWT3G5DEEQX62STJQBY367NL/vendor-advisory
- https://lists.debian.org/debian-lts-announce/2025/07/msg00014.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5HVUXKYTBWT3G5DEEQX62STJQBY367NL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/INKSSLW5VMZIXHRPZBAW4TJUX5SQKARG/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VRDJCNQP32LV56KESUQ5SNZKAJWSZZRI/
- https://www.postgresql.org/support/security/CVE-2026-6472/euvd
- https://nvd.nist.gov/vuln/detail/CVE-2026-6472web
- https://openssl-library.org/news/secadv/20260609.txtvendor-advisory
- https://github.com/openssl/openssl/commit/f04b377be3d821741c86d1f4bf84dee09f3d5c3epatch
- https://github.com/openssl/openssl/commit/a2ca7b2d73e0ffc1eae183fe6e1741dac767cb4fpatch
- https://github.com/openssl/openssl/commit/bbb151a83041705d9d001ed2f9c12f5523e1b54dpatch
- https://github.com/openssl/openssl/commit/dd68364107a58841c0a2546812518b65d3a23abdpatch
- https://access.redhat.com/errata/RHSA-2026:13274euvd
- https://access.redhat.com/security/cve/CVE-2026-3832euvd
- https://bugzilla.redhat.com/show_bug.cgi?id=2445762euvd
Linked CVEs
- CVE-2026-9547
A flaw was found in curl.
criticalCVSSv3 9.1 - CVE-2026-9256
A flaw was found in the ngx_http_rewrite_module module of NGINX.
criticalCVSSv3 8.1 - CVE-2026-9076
A flaw was found in OpenSSL.
highCVSSv3 7.5 - CVE-2026-8286
A flaw was found in curl.
highCVSSv3 8.1 - CVE-2026-7383
A flaw was found in OpenSSL.
highCVSSv3 8.1 - CVE-2026-6637
A flaw was found in PostgreSQL.
highCVSSv3 8.8 - CVE-2026-6479
A flaw was found in PostgreSQL.
highCVSSv3 7.5 - CVE-2026-6478
A flaw was found in PostgreSQL.
mediumCVSSv3 6.5 - CVE-2026-6477
A flaw was found in PostgreSQL libpq.
highCVSSv3 8.8 - CVE-2026-6475
A flaw was found in PostgreSQL.
highCVSSv3 8.8 - CVE-2026-6474
A flaw was found in PostgreSQL.
mediumCVSSv3 4.3 - CVE-2026-6473
A flaw was found in PostgreSQL.
highCVSSv3 8.8 - CVE-2026-6472
A flaw was found in PostgreSQL CREATE TYPE handling for multirange types.
mediumCVSSv3 5.4 - CVE-2026-6238
A flaw was found in glibc (GNU C Library).
mediumCVSSv3 6.5 - CVE-2026-60002
A flaw was found in OpenSSH.
highCVSSv3 7.7 - CVE-2026-59996
A flaw was found in OpenSSH, a widely used tool for secure remote access.
mediumCVSSv3 4.2 - CVE-2026-59858
A command injection vulnerability in Vim's C omni-completion script allows an attacker to execute arbitrary commands if a user is tricked…
highCVSSv3 7.8 - CVE-2026-59856
A flaw was found in Vim, an open-source command-line text editor.
highCVSSv3 7.8 - CVE-2026-5928
A flaw was found in glibc (GNU C Library).
highCVSSv3 7.5 - CVE-2026-58055
A flaw in nghttp2's nghttpx proxy allows a remote attacker to perform HTTP request smuggling and cross-client response-queue poisoning.
mediumCVSSv3 5.4 - CVE-2026-58016
A flaw was found in GLib.
criticalCVSSv3 9.1 - CVE-2026-58015
A flaw was found in GLib.
highCVSSv3 7.5 - CVE-2026-58013
A flaw was found in GLib.
highCVSSv3 8.2 - CVE-2026-58012
A flaw was found in GLib.
highCVSSv3 8.2
Show 93 more CVEs
- CVE-2026-58011
A flaw was found in GLib.
highCVSSv3 7.5 - CVE-2026-58010
A flaw was found in GLib.
highCVSSv3 8.2 - CVE-2026-57456
There is a security flaw in Vim.
highCVSSv3 7.8 - CVE-2026-57455
A memory corruption flaw in Vim allows an attacker to cause a Denial of Service (DoS).
highCVSSv3 7.8 - CVE-2026-55693
A flaw was found in Vim, an open-source command-line text editor.
highCVSSv3 7.8 - CVE-2026-55655
A flaw was found in OpenSSH.
mediumCVSSv3 6.1 - CVE-2026-55654
A flaw was found in OpenSSH.
lowCVSSv3 3.7 - CVE-2026-55653
A flaw was found in OpenSSH.
mediumCVSSv3 6.5 - CVE-2026-5450
A flaw was found in glibc (GNU C Library).
criticalCVSSv3 9.8 - CVE-2026-54370
A time-of-check to time-of-use (TOCTOU) race condition vulnerability was found in `acl`.
highCVSSv3 6.3 - CVE-2026-54369
acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file()…
highCVSSv3 7.1 - CVE-2026-5435
A flaw was found in glibc, the GNU C Library.
highCVSSv3 8.6 - CVE-2026-5419
A flaw was found in gnutls.
lowCVSSv3 3.7 - CVE-2026-52858
A flaw was found in Vim, a widely used command-line text editor.
high - CVE-2026-5260
A flaw was found in libgnutls.
highCVSSv3 8.2 - CVE-2026-48864
A flaw was found in libsolv.
highCVSSv3 7.8 - CVE-2026-4878
A flaw was found in libcap.
highCVSSv3 7.0 - CVE-2026-47167
A flaw was found in Vim, a command-line text editor.
medium - CVE-2026-47162
A flaw was found in Vim, an open-source text editor.
highCVSSv3 8.8 - CVE-2026-46483
A flaw was found in Vim.
lowCVSSv3 3.6 - CVE-2026-45447
A flaw was found in OpenSSL.
highCVSSv3 8.8 - CVE-2026-45446
A flaw was found in OpenSSL.
mediumCVSSv3 4.8 - CVE-2026-45445
A flaw was found in OpenSSL.
highCVSSv3 7.5 - CVE-2026-45409
A flaw was found in the idna library, which handles Internationalized Domain Names in Python applications.
mediumCVSSv3 5.3 - CVE-2026-45186
A flaw was found in libexpat.
highCVSSv3 7.5 - CVE-2026-44432
urllib3 is an HTTP client library for Python.
highCVSSv3 7.5 - CVE-2026-44431
A flaw was found in urllib3, an HTTP client library for Python.
high - CVE-2026-4438
A flaw was found in the GNU C library (glibc).
mediumCVSSv3 5.9 - CVE-2026-4437
A flaw was found in glibc (the GNU C Library).
highCVSSv3 7.5 - CVE-2026-42945
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module.
criticalCVSSv3 8.1 - CVE-2026-42770
A flaw was found in OpenSSL.
lowCVSSv3 3.7 - CVE-2026-42769
A flaw was found in the Certificate Management Protocol (CMP) implementation within OpenSSL.
mediumCVSSv3 5.3 - CVE-2026-42768
A flaw was found in OpenSSL's CMS_decrypt() and PKCS7_decrypt() functions.
lowCVSSv3 3.7 - CVE-2026-42767
A flaw was found in OpenSSL.
mediumCVSSv3 5.9 - CVE-2026-42766
A flaw was found in OpenSSL.
mediumCVSSv3 5.9 - CVE-2026-42764
A flaw was found in the OpenSSL QUIC (Quick UDP Internet Connections) server.
highCVSSv3 7.5 - CVE-2026-4224
A stack overflow flaw has been discovered in the python pyexpat module.
highCVSSv3 7.5 - CVE-2026-42055
A flaw was found in NGINX.
criticalCVSSv3 8.1 - CVE-2026-42015
A flaw was found in gnutls.
mediumCVSSv3 5.3 - CVE-2026-42014
A flaw was found in GnuTLS.
mediumCVSSv3 6.6 - CVE-2026-42013
A flaw was found in gnutls.
highCVSSv3 8.2 - CVE-2026-42012
A flaw was found in gnutls.
highCVSSv3 7.1 - CVE-2026-42011
A flaw was found in gnutls.
highCVSSv3 7.4 - CVE-2026-42010
A flaw was found in gnutls.
criticalCVSSv3 9.8 - CVE-2026-42009
A flaw was found in gnutls.
highCVSSv3 7.5 - CVE-2026-41989
Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.
mediumCVSSv3 6.7 - CVE-2026-41411
A flaw was found in Vim, an open-source command-line text editor.
mediumCVSSv3 6.6 - CVE-2026-4046
A flaw was found in glibc, the GNU C Library.
highCVSSv3 7.5 - CVE-2026-40356
A flaw was found in MIT Kerberos 5 (krb5).
highCVSSv3 7.5 - CVE-2026-40355
A flaw was found in MIT Kerberos 5 (krb5).
mediumCVSSv3 5.9 - CVE-2026-3833
A flaw was found in gnutls.
highCVSSv3 7.4 - CVE-2026-3832
A flaw was found in gnutls.
lowCVSSv3 3.7 - CVE-2026-3783
A flaw was found in curl.
— - CVE-2026-3644
A control character validation flaw has been discovered in the Python http.cookie module.
highCVSSv3 7.5 - CVE-2026-35535
A flaw was found in Sudo.
highCVSSv3 7.8 - CVE-2026-35414
A flaw was found in OpenSSH.
highCVSSv3 8.1 - CVE-2026-35388
A flaw was found in OpenSSH.
lowCVSSv3 2.5 - CVE-2026-35387
A flaw was found in OpenSSH.
mediumCVSSv3 6.5 - CVE-2026-35386
A flaw was found in OpenSSH.
highCVSSv3 8.1 - CVE-2026-35385
A flaw was found in OpenSSH.
highCVSSv3 8.1 - CVE-2026-35177
A flaw was found in Vim's zip.vim plugin.
highCVSSv3 7.1 - CVE-2026-34982
A flaw was found in Vim.
highCVSSv3 8.2 - CVE-2026-34183
A flaw was found in OpenSSL's QUIC PATH_CHALLENGE handler.
highCVSSv3 7.5 - CVE-2026-34182
A flaw was found in OpenSSL's Cryptographic Message Services (CMS) AuthEnvelopedData processing.
criticalCVSSv3 9.1 - CVE-2026-34181
A flaw was found in OpenSSL.
highCVSSv3 7.4 - CVE-2026-34180
A flaw was found in OpenSSL.
highCVSSv3 7.5 - CVE-2026-33846
A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS.
highCVSSv3 7.5 - CVE-2026-33845
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow…
criticalCVSSv3 9.1 - CVE-2026-31790
A flaw was found in openssl.
highCVSSv3 7.5 - CVE-2026-29111
A flaw was found in systemd, a system and service manager.
mediumCVSSv3 5.5 - CVE-2026-28390
A flaw was found in OpenSSL.
highCVSSv3 7.5 - CVE-2026-2297
A flaw was found in CPython.
medium - CVE-2026-2100
A flaw was found in p11-kit.
highCVSSv3 7.5 - CVE-2026-1965
A flaw was found in curl.
— - CVE-2026-15588
A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib.
mediumCVSSv3 5.3 - CVE-2026-15308
A flaw was found in Python.
highCVSSv3 7.5 - CVE-2026-1502
A flaw was found in Python.
medium - CVE-2026-14164
A double free issue has been identified in libarchive's RAR5 reader.
highCVSSv3 7.5 - CVE-2026-13757
A flaw was found in p11-kit.
mediumCVSSv3 6.2 - CVE-2026-11940
A flaw was found in the `tarfile.extractall()` function within Python.
high - CVE-2026-0865
Missing newline filtering has been discovered in Python.
medium - CVE-2026-0672
An injection flaw has been discovered in Python.
medium - CVE-2025-6170
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files.
lowCVSSv3 2.5 - CVE-2025-6075
A vulnerability in Python’s os.path.expandvars() function that can cause performance degradation.
mediumCVSSv3 5.5 - CVE-2025-59375
A memory amplification vulnerability in libexpat allows attackers to trigger excessive dynamic memory allocations by submitting specially…
highCVSSv3 7.5 - CVE-2025-5278
A flaw was found in GNU Coreutils.
mediumCVSSv3 4.4 - CVE-2025-15282
Missing newline filtering has been discovered in Python.
medium - CVE-2025-14512
A flaw was found in glib.
mediumCVSSv3 6.5 - CVE-2025-14087
A flaw was found in GLib (Gnome Lib).
criticalCVSSv3 9.8 - CVE-2025-13837
A flaw was found in the plistlib module in the Python standard library.
mediumCVSSv3 5.5 - CVE-2025-13151
A flaw was found in libtasn1.
— - CVE-2025-10911
A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and appl…
mediumCVSSv3 5.5 - CVE-2024-34459
A flaw was found in the xmllint program distributed by the libxml2 package.
highCVSSv3 7.5