A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.
History

Tue, 27 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.
Title Glib: glib: memory corruption via integer overflow in unicode case conversion
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-787
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-01-27T15:09:09.527Z

Reserved: 2026-01-27T14:00:10.886Z

Link: CVE-2026-1489

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-27T15:15:57.370

Modified: 2026-01-27T15:15:57.370

Link: CVE-2026-1489

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.