CVE-2026-15588 MEDIUM

CVE-2026-15588: Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering

Vendor Red Hat
Product Red Hat Enterprise Linux 10
Weakness CWE-770 · Uncontrolled resource consumption
Published July 20, 2026
Last update July 21, 2026

CVSS base score

5.3/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.

Key dates

02Disclosure timeline

July 20, 2026 CVE published
July 21, 2026 Record updated