CVE-2026-15588

Summary

A denial-of-service and resource exhaustion vulnerability exists within the GDBus component of GLib. The gdbusauth authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.

Affected Software

VendorProductVersion RangeStatus
Red HatRed Hat Enterprise Linux 100:2.80.4-12.el10_2.21 < *unaffected
Red HatRed Hat Enterprise Linux 80:2.56.4-177.el8_10 < *unaffected
Red HatRed Hat Enterprise Linux 90:2.68.4-19.el9_8.9 < *unaffected
Red HatRed Hat Enterprise Linux 90:2.68.4-19.el9_8.9 < *unaffected
Red HatRed Hat Discovery 21788205779 < *unaffected
Red HatRed Hat Discovery 21788206196 < *unaffected
Red HatRed Hat Hardened Images2.89.1-1.1.hum1 < *unaffected
Red HatRed Hat Hardened Images2.89.1-1.2.hum1 < *unaffected
Red HatRed Hat Hardened Images2.89.2-2.hum1 < *unaffected
Red HatRed Hat Update Infrastructure 51787241211 < *unaffected
Red HatRed Hat Update Infrastructure 51787135742 < *unaffected
Red HatRed Hat Update Infrastructure 51787241260 < *unaffected

Weaknesses

  • CWE-770: Allocation of Resources Without Limits or Throttling

Workarounds

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

Additional References

References