
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1485 is a buffer underflow vulnerability in GLib's content type parsing logic that can lead to local denial of service or application instability. The flaw was disclosed on January 27, 2026, and affects GLib across multiple Linux distributions including Red Hat Enterprise Linux, SUSE, Fedora, Debian, and Ubuntu. It carries a CVSS v3.1 base score of 2.8 (Low), reflecting its limited local attack surface and requirement for user interaction (Red Hat CVE, Red Hat Bugzilla).
The root cause is improper handling of header line length in GLib's parse_header() function within the content type parsing logic, classified as CWE-124 (Buffer Underwrite/Buffer Underflow) and CWE-125 (Out-of-bounds Read). Specifically, the length of a header line is stored in a signed integer, which allows integer wraparound when processing extremely large inputs, resulting in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which is used by GLib to determine file content types (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation can cause local denial of service or application instability on affected systems. Because the attack vector is local and requires user interaction (processing a malicious treemagic file), the confidentiality and integrity impacts are none, with only a low availability impact. There is no known potential for remote code execution, lateral movement, or sensitive data exposure based on current analysis (Red Hat CVE, Red Hat Bugzilla).
There is no known public proof-of-concept exploit code, active in-the-wild exploitation, or threat actor attribution associated with CVE-2026-1485. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Nessus (IDs: 297785, 297971, 298230, 298268, 298309, 298314, 298926, 299773) and Qualys (IDs: 6031893, 760844, 6274245) (Red Hat CVE).
Patches have been issued by multiple Linux distributions including Red Hat, SUSE, Fedora, Debian (including LTS via DLA-4491-1), and Ubuntu. Users should update the glib2 (or glib2.0) package to the patched version provided by their respective distribution. No specific configuration-based workaround has been published; upgrading to the fixed package version is the recommended remediation (Red Hat CVE, Debian LTS).
Coverage of CVE-2026-1485 has been limited to routine security update announcements across Linux distribution channels, including pro-linux.de, linuxcompatible.org, and linuxsecurity.com. Dell has referenced this CVE in multiple security advisories (DSA-2026-120, DSA-2026-152, DSA-2026-194, DSA-2026-214) for affected products including Dell Secure Connect Gateway and Dell APEX Cloud Platform. No notable researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."