Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-58012

CVE-2026-58012: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium6.5

    Medium [CVE-2026-58012] buffer over-read in g_regex_replace via glib/gregex.c:string_append and g_utf8_next_char

    CVE-2026-58012Source published Source updated

    A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary. Any applications that use g_regex_replace() or g_regex_replace_eval() with the G_REGEX_RAW compile flag and allow user-controlled replacement strings containing case-change escapes (\u, \l, \U, \L) are vulnerable to this issue. Due to these reasons, this vulnerability has been rated with a moderate severity. Red Hat…

    Affected products in this advisory
    • Red Hat Enterprise Linux 10.0 Extended Update Support
    • Red Hat Enterprise Linux 7 Extended Lifecycle Support
    • Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
    • Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

    19 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • glib2-0:2.80.4-12.el10_2.21
    • glib2-0:2.80.4-4.el10_0.17
    • glib2-0:2.56.1-13.el7_9.1
    • mingw-glib2-0:2.70.1-9.el8_10

    46 more entries in the full advisory.

    Mitigation guidance
    • To mitigate this vulnerability, implement strict input validation to sanitize user-supplied replacement strings, specifically rejecting or escaping case-change modifiers (\u, \l, \U, \L) before calling g_regex_replace() or g_regex_replace_eval() when the G_REGEX_RAW compile flag is used. Removing the G_REGEX_RAW flag or hardcoding the replacement strings will completely neutralize this issue.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery