MinGW Windows GLib2 library
Backport upstream fix for CVE-2026-58014 from GitLab MR !5171 (commit 5f6d86b5) to mingw-glib2 2.70.1. The patch fixes a one-byte heap under-read in g_key_file_get_locale_string_list() when called on a key with an empty value (len == 0). The fix adds a `len > 0` guard in glib/gkeyfile.c. The patch also includes a fuzzing test extension and a unit test. CVE: CVE-2026-58014 Upstream patches: - https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5171.patch Resolves: RHEL-190609 This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent. Assisted-by: Ymir |
||
|---|---|---|
| .gitignore | ||
| 0001-Use-CreateFile-on-Win32-to-make-sure-g_unlink-always.patch | ||
| gating.yaml | ||
| glib-prefer-constructors-over-DllMain.patch | ||
| mingw-glib2-2.70.1-CVE-2026-58014.patch | ||
| mingw-glib2-2.70.1-CVE-2026-58015.patch | ||
| mingw-glib2.spec | ||
| sources | ||