Information on source package glib2.0

Available versions

ReleaseVersion
bookworm2.74.6-2+deb12u9
bookworm (security)2.74.6-2+deb12u2
trixie2.84.4-3~deb13u5
forky2.89.4-2
sid2.90.0-1

Open issues

BugbookwormtrixieforkysidDescription
CVE-2026-86469vulnerablevulnerable (no DSA)vulnerablevulnerableA flaw was found in GLib2. When g_file_replace() is used with G_FILE_C ...
CVE-2026-58016vulnerable (no DSA, postponed)fixedfixedfixedA flaw was found in GLib. A state confusion issue exists in g_dbus_nod ...
CVE-2026-58015vulnerable (no DSA, postponed)fixedfixedfixedA flaw was found in GLib. The D-Bus client-side implementation of the ...
CVE-2026-58014vulnerable (no DSA, postponed)fixedfixedfixedA flaw was found in GLib. An off-by-one error can occur in the g_key_f ...
CVE-2026-58013vulnerable (no DSA, postponed)fixedfixedfixedA flaw was found in GLib. A buffer over-read can occur in g_io_channel ...
CVE-2026-58012vulnerable (no DSA, postponed)fixedfixedfixedA flaw was found in GLib. A buffer over-read can occur in the g_regex_ ...
CVE-2026-58011vulnerable (no DSA, postponed)fixedfixedfixedA flaw was found in GLib. An out-of-bounds read of only 2 bytes can oc ...
CVE-2026-58010vulnerable (no DSA, postponed)fixedfixedfixedA flaw was found in GLib. An off-by-one error can occur in the gvs_tup ...
CVE-2026-16118vulnerable (no DSA, postponed)fixedfixedfixedA flaw was found in xdgmime. A heap-based buffer overflow can be trigg ...
CVE-2026-15588vulnerable (no DSA, postponed)fixedfixedfixedA denial-of-service and resource exhaustion vulnerability exists withi ...

Open unimportant issues

BugbookwormtrixieforkysidDescription
CVE-2012-0039vulnerablevulnerablevulnerablevulnerableGLib 2.31.8 and earlier, when the g_str_hash function is used, compute ...

Resolved issues

BugDescription
CVE-2026-1489A flaw was found in GLib. An integer overflow vulnerability in its Uni ...
CVE-2026-1485A flaw was found in Glib's content type parsing logic. This buffer und ...
CVE-2026-1484A flaw was found in the GLib Base64 encoding routine when processing v ...
CVE-2026-0988A flaw was found in glib. Missing validation of offset and count param ...
CVE-2025-14512A flaw was found in glib. This vulnerability allows a heap buffer over ...
CVE-2025-14087A flaw was found in GLib (Gnome Lib). This vulnerability allows a remo ...
CVE-2025-13601A heap-based buffer overflow problem was found in glib through an inco ...
CVE-2025-7039A flaw was found in glib. An integer overflow during temporary file cr ...
CVE-2025-6052A flaw was found in how GLib\u2019s GString manages memory when adding ...
CVE-2025-4373A flaw was found in GLib, which is vulnerable to an integer overflow i ...
CVE-2025-4056A flaw was found in GLib. A denial of service on Windows platforms may ...
CVE-2025-3360A flaw was found in GLib. An integer overflow and buffer under-read oc ...
CVE-2024-52533gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one erro ...
CVE-2024-34397An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2. ...
CVE-2023-32665A flaw was found in GLib. GVariant deserialization is vulnerable to an ...
CVE-2023-32643A flaw was found in GLib. The GVariant deserialization code is vulnera ...
CVE-2023-32636A flaw was found in glib, where the gvariant deserialization code is v ...
CVE-2023-32611A flaw was found in GLib. GVariant deserialization is vulnerable to a ...
CVE-2023-29499A flaw was found in GLib. GVariant deserialization fails to validate t ...
CVE-2021-28153An issue was discovered in GNOME GLib before 2.66.8. When g_file_repla ...
CVE-2021-27219An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before ...
CVE-2021-27218An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before ...
CVE-2021-3800A flaw was found in glib before version 2.63.6. Due to random charset ...
CVE-2020-35457GNOME GLib before 2.65.3 has an integer overflow, that might lead to a ...
CVE-2020-6750GSocketClient in GNOME GLib through 2.62.4 may occasionally connect di ...
CVE-2019-25085A vulnerability was found in GNOME gvdb. It has been classified as cri ...
CVE-2019-13012The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 ...
CVE-2019-12450file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 ...
CVE-2019-9633gio/gsocketclient.c in GNOME GLib 2.59.2 does not ensure that a parent ...
CVE-2018-16429GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_ ...
CVE-2018-16428In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c ...
CVE-2012-3524libdbus 1.5.x and earlier, when used in setuid or other privileged pro ...
CVE-2009-3289The g_file_copy function in glib 2.0 sets the permissions of a target ...
CVE-2008-4316Multiple integer overflows in glib/gbase64.c in GLib before 2.20 allow ...
CVE-2007-4768Heap-based buffer overflow in Perl-Compatible Regular Expression (PCRE ...
CVE-2007-4767Perl-Compatible Regular Expression (PCRE) library before 7.3 does not ...
CVE-2007-4766Multiple integer overflows in Perl-Compatible Regular Expression (PCRE ...
CVE-2007-1662Perl-Compatible Regular Expression (PCRE) library before 7.3 reads pas ...
CVE-2007-1661Perl-Compatible Regular Expression (PCRE) library before 7.3 backtrack ...
CVE-2007-1660Perl-Compatible Regular Expression (PCRE) library before 7.0 does not ...
CVE-2007-1659Perl-Compatible Regular Expression (PCRE) library before 7.3 allows co ...
CVE-2006-7226Perl-Compatible Regular Expression (PCRE) library before 6.7 does not ...
CVE-2006-7225Perl-Compatible Regular Expression (PCRE) library before 6.7 allows co ...

Security announcements

DSA / DLADescription
DLA-4491-1glib2.0 - security update
DLA-4412-1glib2.0 - security update
DLA-4128-1glib2.0 - security update
DLA-3962-1glib2.0 - security update
DLA-3814-1glib2.0 - security update
DSA-5682-2glib2.0 - regression update
DSA-5682-1glib2.0 - security update
DLA-3583-1glib2.0 - security update
DLA-3110-1glib2.0 - security update
DLA-3044-1glib2.0 - security update
DLA-1866-2glib2.0 - regression update
DLA-1866-1glib2.0 - security update
DLA-1826-1glib2.0 - security update
DSA-1747-1glib2.0 - arbitrary code execution

Search for package or bug name: Reporting problems