CVE-2026-16118
HIGHA flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is...
Full CISO analysis pending enrichment.
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| vLLM | pip | — | No patch |
| vLLM | pip | — | No patch |
| cert-manager/cert-manager-istio-csr-rhel9 | — | — | No patch |
| cert-manager/cert-manager-operator-rhel9 | — | — | No patch |
| cert-manager/cert-manager-trust-manager-rhel9 | — | — | No patch |
| cert-manager/jetstack-cert-manager-acmesolver-rhel9 | — | — | No patch |
| cert-manager/jetstack-cert-manager-rhel9 | — | — | No patch |
| glib2 | — | — | No patch |
| rhai/base-image-cpu-rhel9 | — | — | No patch |
| rhai/base-image-cuda-rhel9 | — | — | No patch |
| rhai/base-image-rocm-rhel9 | — | — | No patch |
| rhai/base-image-spyre-rhel9 | — | — | No patch |
| rhai/base-image-tpu-rhel9 | — | — | No patch |
| rhaiis/model-opt-cuda-rhel9 | — | — | No patch |
| rhui5/cds-kubernetes-rhel9 | — | — | No patch |
| rhui5/cds-rhel9 | — | — | No patch |
| rhui5/haproxy-rhel9 | — | — | No patch |
| rhui5/installer-rhel9 | — | — | No patch |
| rhui5/rhua-rhel9 | — | — | No patch |
| webkit2gtk3 | — | — | No patch |
| webkitgtk4 | — | — | No patch |
| xdgmime | — | — | No patch |
How severe is it?
What is the attack surface?
What should I do?
No patch available
Monitor for updates. Consider compensating controls or temporary mitigations.
Which compliance frameworks are affected?
Compliance analysis pending. Sign in for full compliance mapping when available.
Frequently Asked Questions
What is CVE-2026-16118?
A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.
Is CVE-2026-16118 actively exploited?
No confirmed active exploitation of CVE-2026-16118 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-16118?
No patch is currently available. Monitor vendor advisories for updates.
What is the CVSS score for CVE-2026-16118?
CVE-2026-16118 has a CVSS v3.1 base score of 7.1 (HIGH).
What are the technical details?
Original Advisory
A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.
Weaknesses (CWE)
CWE-122 — Heap-based Buffer Overflow: A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
- Pre-design: Use a language or compiler that performs automatic bounds checking.
- [Architecture and Design] Use an abstraction library to abstract away risky APIs. Not a complete solution.
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H References
- access.redhat.com/errata/RHSA-2026:64799 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:64800 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:66451 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:67956 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:70636 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:71403 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:71404 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:71405 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:72394 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:72395 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:72399 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:72470 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:72475 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:72476 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:72502 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:73859 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:73909 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:73929 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:73930 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:73959 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:73960 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:73961 vendor-advisory x_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:73962 vendor-advisory x_refsource_REDHAT
- access.redhat.com/security/cve/CVE-2026-16118 vdb-entry x_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgi issue-tracking x_refsource_REDHAT
- gitlab.freedesktop.org/xdg/xdgmime/-/work_items/41
Timeline
Related Vulnerabilities
CVE-2026-61732 10.0 Analysis pending
Same package: vllm CVE-2026-25960 9.8 vllm: SSRF allows internal network access
Same package: vllm CVE-2025-47277 9.8 vLLM: RCE via exposed TCPStore in distributed inference
Same package: vllm CVE-2024-11041 9.8 vllm: RCE via unsafe pickle deserialization in MessageQueue
Same package: vllm CVE-2024-9053 9.8 vllm: RCE via unsafe pickle deserialization in RPC server
Same package: vllm