CVE-2026-58014

HIGH
Published June 30, 2026

A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page...

Full CISO analysis pending enrichment.

What systems are affected?

Package Ecosystem Vulnerable Range Patched
vLLM pip — No patch
92.7K 95 dependents Pushed 3d ago 26% patched ~47d to patch Full package profile →
vLLM pip — No patch
92.7K 95 dependents Pushed 3d ago 26% patched ~47d to patch Full package profile →
GLib — — No patch
cert-manager/cert-manager-istio-csr-rhel9 — — No patch
cert-manager/cert-manager-operator-rhel9 — — No patch
cert-manager/cert-manager-trust-manager-rhel9 — — No patch
cert-manager/jetstack-cert-manager-acmesolver-rhel9 — — No patch
cert-manager/jetstack-cert-manager-rhel9 — — No patch
discovery/discovery-server-rhel9 — — No patch
discovery/discovery-ui-rhel9 — — No patch
glib2 — — No patch
mingw-glib2 — — No patch
rhai/base-image-cpu-rhel9 — — No patch
rhai/base-image-cuda-rhel9 — — No patch
rhai/base-image-rocm-rhel9 — — No patch
rhai/base-image-spyre-rhel9 — — No patch
rhai/base-image-tpu-rhel9 — — No patch
rhaiis/model-opt-cuda-rhel9 — — No patch
rhcos — — No patch
rhui5/cds-kubernetes-rhel9 — — No patch
rhui5/cds-kubernetes-tp-rhel9 — — No patch
rhui5/cds-rhel9 — — No patch
rhui5/haproxy-rhel9 — — No patch
rhui5/installer-rhel9 — — No patch
rhui5/installer-tp-rhel9 — — No patch
rhui5/rhua-rhel9 — — No patch
rhui5/rhua-tp-rhel9 — — No patch

How severe is it?

CVSS 3.1
7.3 / 10
EPSS
N/A
Exploitation Status
No known exploitation
Sophistication
N/A

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR None
UI None
S Unchanged
C Low
I Low
A Low

What should I do?

No patch available

Monitor for updates. Consider compensating controls or temporary mitigations.

Which compliance frameworks are affected?

Compliance analysis pending. Sign in for full compliance mapping when available.

Frequently Asked Questions

What is CVE-2026-58014?

A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.

Is CVE-2026-58014 actively exploited?

No confirmed active exploitation of CVE-2026-58014 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-58014?

No patch is currently available. Monitor vendor advisories for updates.

What is the CVSS score for CVE-2026-58014?

CVE-2026-58014 has a CVSS v3.1 base score of 7.3 (HIGH).

What are the technical details?

Original Advisory

A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.

Weaknesses (CWE)

CWE-193 — Off-by-one Error: A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

  • [Implementation] When copying character arrays or using character manipulation methods, the correct size parameter must be used to account for the null terminator that needs to be added at the end of the array. Some examples of functions susceptible to this weakness in C include strcpy(), strncpy(), strcat(), strncat(), printf(), sprintf(), scanf() and sscanf().

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

References

Timeline

Published
June 30, 2026
Last Modified
September 30, 2026
First Seen
September 30, 2026

Related Vulnerabilities