CVE Vulnerabilities

CVE-2026-16118

Heap-based Buffer Overflow

Published: Jul 17, 2026 | Modified: Oct 09, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.1 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.

Weakness

A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatglib2-0:2.80.4-12.el10_2.22*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatglib2-0:2.80.4-4.el10_0.18*
Red Hat Enterprise Linux 8RedHatglib2-0:2.56.4-178.el8_10*
Red Hat Enterprise Linux 9RedHatglib2-0:2.68.4-19.el9_8.10*
Red Hat Enterprise Linux 9RedHatglib2-0:2.68.4-19.el9_8.10*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatglib2-0:2.68.4-7.el9_2.8*
Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsRedHatglib2-0:2.68.4-14.el9_4.9*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatglib2-0:2.68.4-16.el9_6.8*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/jetstack-cert-manager-rhel9:1790223279*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/cert-manager-istio-csr-rhel9:1790223719*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/cert-manager-operator-rhel9:1790272426*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/jetstack-cert-manager-acmesolver-rhel9:1790589998*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/jetstack-cert-manager-rhel9:1790589912*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/cert-manager-istio-csr-rhel9:1790589914*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/cert-manager-operator-rhel9:1790589855*
Cert Manager support for Red Hat OpenShift release 1.20RedHatcert-manager/cert-manager-trust-manager-rhel9:1790598593*
Red Hat AI Inference Server 3.2RedHatrhaiis/model-opt-cuda-rhel9:1790621714*
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-cuda-rhel9:1790621718*
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-rocm-rhel9:1790621713*
Red Hat Cost Management On-Premise 1RedHatcostmanagement/costmanagement-ui-rhel10:1791460851*
Red Hat OpenShift AI 3.0RedHatrhai/base-image-rocm-rhel9:1790276886*
Red Hat OpenShift AI 3.0RedHatrhai/base-image-tpu-rhel9:1790276884*
Red Hat OpenShift AI 3.0RedHatrhai/base-image-cpu-rhel9:1790277045*
Red Hat OpenShift AI 3.0RedHatrhai/base-image-spyre-rhel9:1790276889*
Red Hat OpenShift AI 3.0RedHatrhai/base-image-cuda-rhel9:1790276974*
Red Hat OpenShift AI 3.2RedHatrhai/base-image-tpu-rhel9:1790703497*
Red Hat OpenShift AI 3.2RedHatrhai/base-image-rocm-rhel9:1790703506*
Red Hat OpenShift AI 3.2RedHatrhai/base-image-cpu-rhel9:1790703590*
Red Hat OpenShift AI 3.2RedHatrhai/base-image-spyre-rhel9:1790703568*
Red Hat OpenShift AI 3.2RedHatrhai/base-image-cuda-rhel9:1790703586*
Red Hat OpenShift AI 3.2RedHatrhai/base-image-rocm-rhel9:1790703494*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-cpu-rhel9:1790703615*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-tpu-rhel9:1790703516*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-rocm-6.4-rhel9:1790703524*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-cuda-13.0-rhel9:1790703601*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-rocm-7.0-rhel9:1790703516*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-cuda-12.9-rhel9:1790703608*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-spyre-rhel9:1790703579*
Red Hat OpenShift AI 3.3RedHatrhai/base-image-neuron-rhel9:1790703516*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-neuron-rhel9:1790703542*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-tpu-rhel9:1790703539*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-gaudi-rhel9:1790703553*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-cpu-rhel9:1790703631*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-spyre-rhel9:1790703597*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-cuda-13.0-rhel9:1790703641*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-cuda-12.9-rhel9:1790703630*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-rocm-7.1-rhel9:1790703541*
Red Hat OpenShift AI 3.4RedHatrhai/base-image-rocm-6.4-rhel9:1790703545*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-gaudi-rhel9:1790703552*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-cpu-rhel9:1790703656*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-neuron-rhel9:1790703557*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-rubin-rhel9:1790703707*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-cuda-13.0-rhel9:1790703645*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-tpu-rhel9:1790703554*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-rocm-7.14-rhel9:1790703554*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-spyre-rhel9:1790703630*
Red Hat OpenShift AI 3.5RedHatrhai/base-image-cuda-12.9-rhel9:1790703706*
Red Hat Update Infrastructure 5RedHatrhui5/cds-kubernetes-rhel9:1789479916*
Red Hat Update Infrastructure 5RedHatrhui5/cds-rhel9:1789479900*
Red Hat Update Infrastructure 5RedHatrhui5/haproxy-rhel9:1789479891*
Red Hat Update Infrastructure 5RedHatrhui5/installer-rhel9:1789482961*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-rhel9:1789478095*
Glib2.0Ubuntuesm-infra-legacy/trusty*
Glib2.0Ubuntuesm-infra-legacy/xenial*
Glib2.0Ubuntuesm-infra/bionic*
Glib2.0Ubuntuesm-infra/focal*
Glib2.0Ubuntujammy*
Glib2.0Ubuntunoble*
Glib2.0Ubunturesolute*
Glib2.0Ubuntuupstream*

Potential Mitigations

  • Use automatic buffer overflow detection mechanisms that are offered by certain compilers or compiler extensions. Examples include: the Microsoft Visual Studio /GS flag, Fedora/Red Hat FORTIFY_SOURCE GCC flag, StackGuard, and ProPolice, which provide various mechanisms including canary-based detection and range/index checking.
  • D3-SFCV (Stack Frame Canary Validation) from D3FEND [REF-1334] discusses canary-based detection in detail.
  • Run or compile the software using features or extensions that randomly arrange the positions of a program’s executable and libraries in memory. Because this makes the addresses unpredictable, it can prevent an attacker from reliably jumping to exploitable code.
  • Examples include Address Space Layout Randomization (ASLR) [REF-58] [REF-60] and Position-Independent Executables (PIE) [REF-64]. Imported modules may be similarly realigned if their default memory addresses conflict with other modules, in a process known as “rebasing” (for Windows) and “prelinking” (for Linux) [REF-1332] using randomly generated addresses. ASLR for libraries cannot be used in conjunction with prelink since it would require relocating the libraries at run-time, defeating the whole purpose of prelinking.
  • For more information on these techniques see D3-SAOR (Segment Address Offset Randomization) from D3FEND [REF-1335].

References