MinGW Windows GLib2 library
Go to file
RHEL Packaging Agent 8e46bdc457 Fix CVE-2026-58015: D-Bus cookie context path traversal
Backport upstream fix for CVE-2026-58015 which validates
D-Bus SHA-1 authentication cookie contexts to prevent
path traversal attacks. The patch includes five upstream
commits that add cookie context validation, cookie ID range
checks, and hardening of the keyring file parser, with
C99 types adapted to GLib equivalents for compatibility
with the older GLib 2.70.1 codebase.

CVE: CVE-2026-58015
Upstream patches:
 - https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5172.patch
Resolves: RHEL-212246

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
2026-07-22 16:17:37 +00:00
.gitignore Import rpm: c8s 2023-02-27 14:24:00 -05:00
0001-Use-CreateFile-on-Win32-to-make-sure-g_unlink-always.patch Auto sync2gitlab import of mingw-glib2-2.70.1-1.el8_5.src.rpm 2022-05-26 11:33:06 -04:00
gating.yaml Bring gating.yaml over from Brew dist-git 2023-03-10 11:04:29 -08:00
glib-prefer-constructors-over-DllMain.patch Auto sync2gitlab import of mingw-glib2-2.70.1-1.el8_5.src.rpm 2022-05-26 11:33:06 -04:00
mingw-glib2-2.70.1-CVE-2026-58015.patch Fix CVE-2026-58015: D-Bus cookie context path traversal 2026-07-22 16:17:37 +00:00
mingw-glib2.spec Fix CVE-2026-58015: D-Bus cookie context path traversal 2026-07-22 16:17:37 +00:00
sources Auto sync2gitlab import of mingw-glib2-2.70.1-1.el8_5.src.rpm 2022-05-26 11:33:06 -04:00