← All Advisories

CVE-2026-16118

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-16118

Key Details

CVECVE-2026-16118
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is none; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-122 (Heap-based Buffer Overflow)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat OpenShift AI 3.3
Red HatRed Hat OpenShift AI 3.4
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat OpenShift AI 3.5
Red HatRed Hat Update Infrastructure 5
Red HatCert Manager support for Red Hat OpenShift release 1.20
Red HatRed Hat AI Inference Server 3.2
Red HatRed Hat OpenShift AI 3.0
Red HatRed Hat OpenShift AI 3.2
xdgxdgmime
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption. (NVD)

What to Do

Monitor Red Hat's and xdg's web pages for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-16118
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-16118