{
    "summary": {
        "snap": {
            "added": [],
            "removed": [],
            "diff": []
        },
        "deb": {
            "added": [],
            "removed": [],
            "diff": [
                "gir1.2-glib-2.0",
                "libexpat1",
                "libglib2.0-0t64"
            ]
        }
    },
    "diff": {
        "deb": [
            {
                "name": "gir1.2-glib-2.0",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.80.0-6ubuntu3.8",
                    "version": "2.80.0-6ubuntu3.8"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.80.0-6ubuntu3.9",
                    "version": "2.80.0-6ubuntu3.9"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-58010",
                        "url": "https://ubuntu.com/security/CVE-2026-58010",
                        "cve_description": "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58011",
                        "url": "https://ubuntu.com/security/CVE-2026-58011",
                        "cve_description": "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58012",
                        "url": "https://ubuntu.com/security/CVE-2026-58012",
                        "cve_description": "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58013",
                        "url": "https://ubuntu.com/security/CVE-2026-58013",
                        "cve_description": "A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58014",
                        "url": "https://ubuntu.com/security/CVE-2026-58014",
                        "cve_description": "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58015",
                        "url": "https://ubuntu.com/security/CVE-2026-58015",
                        "cve_description": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58010",
                                "url": "https://ubuntu.com/security/CVE-2026-58010",
                                "cve_description": "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58011",
                                "url": "https://ubuntu.com/security/CVE-2026-58011",
                                "cve_description": "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58012",
                                "url": "https://ubuntu.com/security/CVE-2026-58012",
                                "cve_description": "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58013",
                                "url": "https://ubuntu.com/security/CVE-2026-58013",
                                "cve_description": "A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58014",
                                "url": "https://ubuntu.com/security/CVE-2026-58014",
                                "cve_description": "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58015",
                                "url": "https://ubuntu.com/security/CVE-2026-58015",
                                "cve_description": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: off-by-one OOB read in GVariant serialiser",
                            "    - debian/patches/CVE-2026-58010.patch: fix bounds check to use >= instead",
                            "      of > in gvs_tuple_is_normal() in glib/gvariant-serialiser.c.",
                            "    - CVE-2026-58010",
                            "  * SECURITY UPDATE: OOB read in GDateTime",
                            "    - debian/patches/CVE-2026-58011.patch: add missing range validation to",
                            "      g_date_time_add_full() in glib/gdatetime.c.",
                            "    - CVE-2026-58011",
                            "  * SECURITY UPDATE: buffer over-read in g_regex_replace",
                            "    - debian/patches/CVE-2026-58012.patch: fix case-change substitution",
                            "      handling with G_REGEX_RAW in glib/gregex.c.",
                            "    - CVE-2026-58012",
                            "  * SECURITY UPDATE: buffer over-read in GIOChannel",
                            "    - debian/patches/CVE-2026-58013.patch: add length check before memcmp",
                            "      in g_io_channel_read_line_backend() in glib/giochannel.c.",
                            "    - CVE-2026-58013",
                            "  * SECURITY UPDATE: off-by-one heap under-read in GKeyFile",
                            "    - debian/patches/CVE-2026-58014.patch: add len > 0 check before",
                            "      accessing value[len-1] in g_key_file_get_locale_string_list() in",
                            "      glib/gkeyfile.c.",
                            "    - CVE-2026-58014",
                            "  * SECURITY UPDATE: path traversal in DBUS_COOKIE_SHA1 auth",
                            "    - debian/patches/CVE-2026-58015.patch: validate cookie_context parameter",
                            "      to prevent path traversal in gio/gdbusauthmechanismsha1.c.",
                            "    - CVE-2026-58015",
                            "  * SECURITY UPDATE: state confusion in D-Bus introspection XML parser",
                            "    - debian/patches/CVE-2026-58016.patch: fix node element nesting check",
                            "      and add assertions in gio/gdbusintrospection.c.",
                            "    - CVE-2026-58016",
                            "  * SECURITY UPDATE: resource exhaustion in GDBus authentication",
                            "    - debian/patches/CVE-2026-15588.patch: limit length of lines read from",
                            "      client in gio/gdbusauth.c.",
                            "    - CVE-2026-15588",
                            "  * SECURITY UPDATE: heap buffer overflow in xdgmime",
                            "    - debian/patches/CVE-2026-16118.patch: fix pointer arithmetic in",
                            "      byte-swap routine in gio/xdgmime/xdgmimemagic.c.",
                            "    - CVE-2026-16118",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.80.0-6ubuntu3.9",
                        "urgency": "medium",
                        "distributions": "noble-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Leonidas Da Silva Barbosa <leo.barbosa@canonical.com>",
                        "date": "Tue, 08 Sep 2026 14:07:47 -0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libexpat1",
                "from_version": {
                    "source_package_name": "expat",
                    "source_package_version": "2.6.1-2ubuntu0.4",
                    "version": "2.6.1-2ubuntu0.4"
                },
                "to_version": {
                    "source_package_name": "expat",
                    "source_package_version": "2.6.1-2ubuntu0.5",
                    "version": "2.6.1-2ubuntu0.5"
                },
                "cves": [
                    {
                        "cve": "CVE-2025-59375",
                        "url": "https://ubuntu.com/security/CVE-2025-59375",
                        "cve_description": "libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.",
                        "cve_priority": "medium",
                        "cve_public_date": "2025-09-15 03:15:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-32776",
                        "url": "https://ubuntu.com/security/CVE-2026-32776",
                        "cve_description": "libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-16 14:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-32777",
                        "url": "https://ubuntu.com/security/CVE-2026-32777",
                        "cve_description": "libexpat before 2.7.5 allows an infinite loop while parsing DTD content.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-16 14:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-32778",
                        "url": "https://ubuntu.com/security/CVE-2026-32778",
                        "cve_description": "libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-03-16 14:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-45186",
                        "url": "https://ubuntu.com/security/CVE-2026-45186",
                        "cve_description": "In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-05-10 07:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-41080",
                        "url": "https://ubuntu.com/security/CVE-2026-41080",
                        "cve_description": "libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-04-16 17:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56408",
                        "url": "https://ubuntu.com/security/CVE-2026-56408",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in copyString.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56403",
                        "url": "https://ubuntu.com/security/CVE-2026-56403",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in storeAtts.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-50219",
                        "url": "https://ubuntu.com/security/CVE-2026-50219",
                        "cve_description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-04 06:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56412",
                        "url": "https://ubuntu.com/security/CVE-2026-56412",
                        "cve_description": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 17:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56404",
                        "url": "https://ubuntu.com/security/CVE-2026-56404",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in addBinding.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-56405",
                        "url": "https://ubuntu.com/security/CVE-2026-56405",
                        "cve_description": "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-21 16:16:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2025-59375",
                                "url": "https://ubuntu.com/security/CVE-2025-59375",
                                "cve_description": "libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.",
                                "cve_priority": "medium",
                                "cve_public_date": "2025-09-15 03:15:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-32776",
                                "url": "https://ubuntu.com/security/CVE-2026-32776",
                                "cve_description": "libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-16 14:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-32777",
                                "url": "https://ubuntu.com/security/CVE-2026-32777",
                                "cve_description": "libexpat before 2.7.5 allows an infinite loop while parsing DTD content.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-16 14:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-32778",
                                "url": "https://ubuntu.com/security/CVE-2026-32778",
                                "cve_description": "libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-03-16 14:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-45186",
                                "url": "https://ubuntu.com/security/CVE-2026-45186",
                                "cve_description": "In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-05-10 07:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-41080",
                                "url": "https://ubuntu.com/security/CVE-2026-41080",
                                "cve_description": "libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-04-16 17:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56408",
                                "url": "https://ubuntu.com/security/CVE-2026-56408",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in copyString.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56403",
                                "url": "https://ubuntu.com/security/CVE-2026-56403",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in storeAtts.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-50219",
                                "url": "https://ubuntu.com/security/CVE-2026-50219",
                                "cve_description": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-04 06:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56412",
                                "url": "https://ubuntu.com/security/CVE-2026-56412",
                                "cve_description": "libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 17:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56404",
                                "url": "https://ubuntu.com/security/CVE-2026-56404",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in addBinding.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-56405",
                                "url": "https://ubuntu.com/security/CVE-2026-56405",
                                "cve_description": "libexpat before 2.8.2 has an integer overflow in getAttributeId.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-21 16:16:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: large dynamic memory allocations via a small document",
                            "    - debian/patches/CVE-2025-59375-1.patch: lib: Make function dtdCreate use",
                            "      macro MALLOC in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2025-59375-2.patch: lib: Make string pools use macros",
                            "      MALLOC, FREE, REALLOC in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2025-59375-3.patch: lib: Make function hash tables use",
                            "      macros MALLOC and FREE in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2025-59375-4.patch: lib: Make function copyString use",
                            "      macro MALLOC in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2025-59375-5.patch: lib: Make function dtdReset use",
                            "      macro FREE in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2025-59375-6.patch: lib: Make function dtdDestroy use",
                            "      macro FREE in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2025-59375-7.patch: lib: Make function dtdCopy use",
                            "      macro MALLOC in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2025-59375-8.patch: lib: Implement tracking of dynamic",
                            "      memory allocations in .github/workflows/data/exported-symbols.txt,",
                            "      expat/lib/expat.h, expat/lib/internal.h, expat/lib/libexpat.def.cmake,",
                            "      expat/lib/xmlparse.c, expat/tests/basic_tests.c,",
                            "      expat/tests/nsalloc_tests.c, expat/xmlwf/xmlwf.c,",
                            "      expat/xmlwf/xmlwf_helpgen.py.",
                            "    - debian/patches/CVE-2025-59375-9.patch: lib: Make XML_MemFree and",
                            "      XML_FreeContentModel match their siblings in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2025-59375-10.patch: lib: Exclude XML_Mem* functions",
                            "      from allocation tracking in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2025-59375-11.patch: lib: Exclude the main input buffer",
                            "      from allocation tracking in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2025-59375-12.patch: lib: Exclude the content model",
                            "      from allocation tracking in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2025-59375-13.patch: tests: Cover allocation tracking",
                            "      and limiting with tests in expat/lib/internal.h, expat/lib/xmlparse.c,",
                            "      expat/tests/alloc_tests.c.",
                            "    - debian/patches/CVE-2025-59375-14.patch: xmlwf: Wire allocation tracker",
                            "      config to existing arguments -a and -b in expat/doc/xmlwf.xml,",
                            "      expat/xmlwf/xmlwf.c, expat/xmlwf/xmlwf_helpgen.py.",
                            "    - debian/patches/CVE-2025-59375-15.patch: fuzz: Be robust towards NULL",
                            "      return from XML_ExternalEntityParserCreate in",
                            "      expat/fuzz/xml_parse_fuzzer.c, expat/fuzz/xml_parsebuffer_fuzzer.c.",
                            "    - debian/patches/CVE-2025-59375-16.patch: lib: Document and regression-proof",
                            "      absence of integer overflow from expat_realloc in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2025-59375-17.patch: lib: Fix alignment of internal",
                            "      allocations for some non-amd64 architectures in expat/lib/internal.h,",
                            "      expat/lib/xmlparse.c, expat/tests/alloc_tests.c.",
                            "    - debian/patches/CVE-2025-59375-18.patch: tests: Fix test guard for test",
                            "      related to allocation tracking in expat/tests/alloc_tests.c.",
                            "    - debian/patches/CVE-2025-59375-19.patch: tests: Add new test",
                            "      test_alloc_tracker_pointer_alignment in expat/tests/alloc_tests.c.",
                            "    - debian/patches/CVE-2025-59375-20.patch: lib: Fix detection of asynchronous",
                            "      tags in entities in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2025-59375-21.patch: tests: Cover",
                            "      XML_ERROR_ASYNC_ENTITY cases in expat/tests/misc_tests.c.",
                            "    - debian/patches/CVE-2025-59375-22.patch: tests: Add line/column checks to",
                            "      async entity tests in expat/tests/misc_tests.c.",
                            "    - CVE-2025-59375",
                            "  * SECURITY UPDATE: NULL function-pointer dereference",
                            "    - debian/patches/CVE-2026-32776.patch: Fix NULL function-pointer dereference",
                            "      for empty external parameter entities in expat/lib/xmlparse.c,",
                            "      expat/tests/basic_tests.c.",
                            "    - CVE-2026-32776",
                            "  * SECURITY UPDATE: infinite loop while parsing DTD content",
                            "    - debian/patches/CVE-2026-32777-1.patch: lib: Reject XML_TOK_INSTANCE_START",
                            "      infinite loop in entityValueProcessor in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-32777-2.patch: misc_tests.c: Cover",
                            "      XML_TOK_INSTANCE_START infinite loop case in expat/tests/misc_tests.c.",
                            "    - CVE-2026-32777",
                            "  * SECURITY UPDATE: NULL pointer dereference",
                            "    - debian/patches/CVE-2026-32778-1.patch: copy prefix name to pool before",
                            "      lookup in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-32778-2.patch: test that we do not end up with a",
                            "      zombie PREFIX in the pool in expat/tests/nsalloc_tests.c.",
                            "    - CVE-2026-32778",
                            "  * SECURITY UPDATE: denial of service via moderately sized crafted XML input",
                            "    - debian/patches/CVE-2026-45186-1.patch: Make",
                            "      \"counting_start_element_handler\" count default attrs in",
                            "      expat/tests/basic_tests.c, expat/tests/handlers.c, expat/tests/handlers.h.",
                            "    - debian/patches/CVE-2026-45186-2.patch: test(attlist): Cover duplicate",
                            "      attribute names in expat/tests/basic_tests.c.",
                            "    - debian/patches/CVE-2026-45186-3-pre.patch: tests: Migrate test_attributes",
                            "      off of g_parser in expat/tests/basic_tests.c.",
                            "    - debian/patches/CVE-2026-45186-3.patch: tests: Define .attributes the first",
                            "      time around in expat/tests/basic_tests.c.",
                            "    - debian/patches/CVE-2026-45186-4.patch: tests: Make",
                            "      counting_start_element_handler enforce complete attribute lists in",
                            "      expat/tests/handlers.c.",
                            "    - debian/patches/CVE-2026-45186-5.patch: lib: Extract a constant for",
                            "      upcoming reuse in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-45186-6.patch: lib: Introduce",
                            "      ELEMENT_TYPE.defaultAttsNames in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-45186-7.patch: lib: Leverage",
                            "      ELEMENT_TYPE.defaultAttsNames for attribute collision detection in",
                            "      expat/lib/xmlparse.c.",
                            "    - CVE-2026-45186",
                            "  * SECURITY UPDATE: hash flooding caused by insufficient entropy",
                            "    - debian/patches/CVE-2026-41080-1-pre.patch: lib/xmlparse.c: Address clang-",
                            "      tidy warning misc-no-recursion in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-1.patch: lib: Inline function",
                            "      `get_hash_secret_salt` in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-2.patch: lib: Drop unused parameter from",
                            "      function `generate_hash_secret_salt` in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-3.patch: lib: Migrate hash salt storage to",
                            "      larger `struct sipkey` in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-4.patch: lib: Drop unneeded `void *` casts",
                            "      in function `generate_hash_secret_salt` in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-5-pre.patch: WASI: remove getpid in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-5.patch: lib: Extract 16 bytes of entropy",
                            "      (instead of 4 to 8) for hash flooding protection in expat/lib/internal.h,",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-6.patch: lib: Introduce internal flag",
                            "      `m_hash_secret_salt_set` in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-7.patch: lib: Introduce API function",
                            "      `XML_SetHashSalt16Bytes` in expat/lib/expat.h, expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-8.patch: lib: Include `XML_SetHashSalt*`",
                            "      with entropy debugging in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-9.patch: tests: Add basic coverage to",
                            "      `XML_SetHashSalt16Bytes` in expat/tests/basic_tests.c.",
                            "    - debian/patches/CVE-2026-41080-10.patch: doc: Document `XML_SetHashSalt` as",
                            "      being deprecated in expat/lib/expat.h, expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-41080-11.patch: cmake|windows: add missing export",
                            "      for new XML_SetHashSalt16Bytes in expat/lib/libexpat.def.cmake.",
                            "    - CVE-2026-41080",
                            "  * SECURITY UPDATE: integer overflow",
                            "    - debian/patches/CVE-2026-56408.patch: lib: Waterproof `copyString` from",
                            "      integer overflow in expat/lib/xmlparse.c.",
                            "    - CVE-2026-56408",
                            "  * SECURITY UPDATE: integer overflow",
                            "    - debian/patches/CVE-2026-56403-pre1.patch: Replace the empty for-loops with",
                            "      while loops in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-56403-1.patch: lib: Protect function `storeAtts`",
                            "      from signed integer overflow in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-56403-2.patch: xmlwf: Protect function `xcsdup`",
                            "      from signed integer overflow in expat/xmlwf/xmlwf.c.",
                            "    - CVE-2026-56403",
                            "  * SECURITY UPDATE: use after free",
                            "    - debian/patches/CVE-2026-50219-1.patch: lib: Introduce handler call depth",
                            "      tracking in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-2.patch: lib: Prepare",
                            "      `m_notStandaloneHandler` calls for upcoming wrapping in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-3.patch: lib: Prepare",
                            "      `m_externalEntityRefHandler` calls for upcoming wrapping in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-4.patch: lib: Prepare",
                            "      `m_unknownEncodingHandler` calls for upcoming wrapping in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-5.patch: lib: Register",
                            "      `m_attlistDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-6.patch: lib: Register",
                            "      `m_characterDataHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-7.patch: lib: Register `m_commentHandler`",
                            "      with handler call depth tracking in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-8.patch: lib: Register `m_defaultHandler`",
                            "      with handler call depth tracking in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-9.patch: lib: Register",
                            "      `m_elementDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-10.patch: lib: Register",
                            "      `m_endCdataSectionHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-11.patch: lib: Register",
                            "      `m_endDoctypeDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-12.patch: lib: Register",
                            "      `m_endElementHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-13.patch: lib: Register",
                            "      `m_endNamespaceDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-14.patch: lib: Register",
                            "      `m_entityDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-15.patch: lib: Register",
                            "      `m_externalEntityRefHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-16.patch: lib: Register",
                            "      `m_notationDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-17.patch: lib: Register",
                            "      `m_notStandaloneHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-18.patch: lib: Register",
                            "      `m_processingInstructionHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-19.patch: lib: Register",
                            "      `m_skippedEntityHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-20.patch: lib: Register",
                            "      `m_startCdataSectionHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-21.patch: lib: Register",
                            "      `m_startDoctypeDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-22.patch: lib: Register",
                            "      `m_startElementHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-23.patch: lib: Register",
                            "      `m_startNamespaceDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-24.patch: lib: Register",
                            "      `m_unknownEncodingHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-25.patch: lib: Register",
                            "      `m_unparsedEntityDeclHandler` with handler call depth tracking in",
                            "      expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-26.patch: lib: Register `m_xmlDeclHandler`",
                            "      with handler call depth tracking in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-27.patch: lib: Protect `XML_GetBuffer` from",
                            "      being called from a handler in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-28.patch: lib: Protect `XML_Parse` from",
                            "      being called from a handler in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-29.patch: lib: Protect `XML_ParseBuffer`",
                            "      from being called from a handler in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-30.patch: lib: Protect `XML_ParserFree` from",
                            "      being called from a handler in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-31.patch: lib: Protect `XML_ParserReset`",
                            "      from being called from a handler in expat/lib/xmlparse.c.",
                            "    - debian/patches/CVE-2026-50219-32.patch: tests: Cover calls forbidden from",
                            "      handlers in expat/tests/handlers.c, expat/tests/handlers.h,",
                            "      expat/tests/misc_tests.c.",
                            "    - CVE-2026-50219",
                            "  * SECURITY UPDATE: use after free (fix for CVE-2026-50219 was incomplete)",
                            "    - debian/patches/CVE-2026-56412.patch: lib: guard XML_TOK_DATA_CHARS handler",
                            "      calls in doCdataSection() in expat/lib/xmlparse.c.",
                            "    - CVE-2026-56412",
                            "  * SECURITY UPDATE: integer overflow",
                            "    - debian/patches/CVE-2026-56404.patch: lib: protect function addBinding from",
                            "      signed integer overflow in expat/lib/xmlparse.c.",
                            "    - CVE-2026-56404",
                            "  * SECURITY UPDATE: integer overflow",
                            "    - debian/patches/CVE-2026-56405.patch: lib: Protect function getAttributeId",
                            "      from signed integer overflow in expat/lib/xmlparse.c.",
                            "    - CVE-2026-56405",
                            ""
                        ],
                        "package": "expat",
                        "version": "2.6.1-2ubuntu0.5",
                        "urgency": "medium",
                        "distributions": "noble-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Isabel Garcia Contreras <isabel.garcia@canonical.com>",
                        "date": "Fri, 11 Sep 2026 10:26:31 -0400"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            },
            {
                "name": "libglib2.0-0t64",
                "from_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.80.0-6ubuntu3.8",
                    "version": "2.80.0-6ubuntu3.8"
                },
                "to_version": {
                    "source_package_name": "glib2.0",
                    "source_package_version": "2.80.0-6ubuntu3.9",
                    "version": "2.80.0-6ubuntu3.9"
                },
                "cves": [
                    {
                        "cve": "CVE-2026-58010",
                        "url": "https://ubuntu.com/security/CVE-2026-58010",
                        "cve_description": "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58011",
                        "url": "https://ubuntu.com/security/CVE-2026-58011",
                        "cve_description": "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58012",
                        "url": "https://ubuntu.com/security/CVE-2026-58012",
                        "cve_description": "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58013",
                        "url": "https://ubuntu.com/security/CVE-2026-58013",
                        "cve_description": "A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58014",
                        "url": "https://ubuntu.com/security/CVE-2026-58014",
                        "cve_description": "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58015",
                        "url": "https://ubuntu.com/security/CVE-2026-58015",
                        "cve_description": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-58016",
                        "url": "https://ubuntu.com/security/CVE-2026-58016",
                        "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-06-30 13:19:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-15588",
                        "url": "https://ubuntu.com/security/CVE-2026-15588",
                        "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-20 12:17:00 UTC"
                    },
                    {
                        "cve": "CVE-2026-16118",
                        "url": "https://ubuntu.com/security/CVE-2026-16118",
                        "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                        "cve_priority": "medium",
                        "cve_public_date": "2026-07-17 20:17:00 UTC"
                    }
                ],
                "launchpad_bugs_fixed": [],
                "changes": [
                    {
                        "cves": [
                            {
                                "cve": "CVE-2026-58010",
                                "url": "https://ubuntu.com/security/CVE-2026-58010",
                                "cve_description": "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58011",
                                "url": "https://ubuntu.com/security/CVE-2026-58011",
                                "cve_description": "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58012",
                                "url": "https://ubuntu.com/security/CVE-2026-58012",
                                "cve_description": "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58013",
                                "url": "https://ubuntu.com/security/CVE-2026-58013",
                                "cve_description": "A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58014",
                                "url": "https://ubuntu.com/security/CVE-2026-58014",
                                "cve_description": "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58015",
                                "url": "https://ubuntu.com/security/CVE-2026-58015",
                                "cve_description": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-58016",
                                "url": "https://ubuntu.com/security/CVE-2026-58016",
                                "cve_description": "A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-06-30 13:19:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-15588",
                                "url": "https://ubuntu.com/security/CVE-2026-15588",
                                "cve_description": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-20 12:17:00 UTC"
                            },
                            {
                                "cve": "CVE-2026-16118",
                                "url": "https://ubuntu.com/security/CVE-2026-16118",
                                "cve_description": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
                                "cve_priority": "medium",
                                "cve_public_date": "2026-07-17 20:17:00 UTC"
                            }
                        ],
                        "log": [
                            "",
                            "  * SECURITY UPDATE: off-by-one OOB read in GVariant serialiser",
                            "    - debian/patches/CVE-2026-58010.patch: fix bounds check to use >= instead",
                            "      of > in gvs_tuple_is_normal() in glib/gvariant-serialiser.c.",
                            "    - CVE-2026-58010",
                            "  * SECURITY UPDATE: OOB read in GDateTime",
                            "    - debian/patches/CVE-2026-58011.patch: add missing range validation to",
                            "      g_date_time_add_full() in glib/gdatetime.c.",
                            "    - CVE-2026-58011",
                            "  * SECURITY UPDATE: buffer over-read in g_regex_replace",
                            "    - debian/patches/CVE-2026-58012.patch: fix case-change substitution",
                            "      handling with G_REGEX_RAW in glib/gregex.c.",
                            "    - CVE-2026-58012",
                            "  * SECURITY UPDATE: buffer over-read in GIOChannel",
                            "    - debian/patches/CVE-2026-58013.patch: add length check before memcmp",
                            "      in g_io_channel_read_line_backend() in glib/giochannel.c.",
                            "    - CVE-2026-58013",
                            "  * SECURITY UPDATE: off-by-one heap under-read in GKeyFile",
                            "    - debian/patches/CVE-2026-58014.patch: add len > 0 check before",
                            "      accessing value[len-1] in g_key_file_get_locale_string_list() in",
                            "      glib/gkeyfile.c.",
                            "    - CVE-2026-58014",
                            "  * SECURITY UPDATE: path traversal in DBUS_COOKIE_SHA1 auth",
                            "    - debian/patches/CVE-2026-58015.patch: validate cookie_context parameter",
                            "      to prevent path traversal in gio/gdbusauthmechanismsha1.c.",
                            "    - CVE-2026-58015",
                            "  * SECURITY UPDATE: state confusion in D-Bus introspection XML parser",
                            "    - debian/patches/CVE-2026-58016.patch: fix node element nesting check",
                            "      and add assertions in gio/gdbusintrospection.c.",
                            "    - CVE-2026-58016",
                            "  * SECURITY UPDATE: resource exhaustion in GDBus authentication",
                            "    - debian/patches/CVE-2026-15588.patch: limit length of lines read from",
                            "      client in gio/gdbusauth.c.",
                            "    - CVE-2026-15588",
                            "  * SECURITY UPDATE: heap buffer overflow in xdgmime",
                            "    - debian/patches/CVE-2026-16118.patch: fix pointer arithmetic in",
                            "      byte-swap routine in gio/xdgmime/xdgmimemagic.c.",
                            "    - CVE-2026-16118",
                            ""
                        ],
                        "package": "glib2.0",
                        "version": "2.80.0-6ubuntu3.9",
                        "urgency": "medium",
                        "distributions": "noble-security",
                        "launchpad_bugs_fixed": [],
                        "author": "Leonidas Da Silva Barbosa <leo.barbosa@canonical.com>",
                        "date": "Tue, 08 Sep 2026 14:07:47 -0300"
                    }
                ],
                "notes": null,
                "is_version_downgrade": false
            }
        ],
        "snap": []
    },
    "added": {
        "deb": [],
        "snap": []
    },
    "removed": {
        "deb": [],
        "snap": []
    },
    "notes": "Changelog diff for Ubuntu 24.04 noble image from daily image serial 20260918 to 20260922",
    "from_series": "noble",
    "to_series": "noble",
    "from_serial": "20260918",
    "to_serial": "20260922",
    "from_manifest_filename": "daily_manifest.previous",
    "to_manifest_filename": "manifest.current"
}