← All Advisories

CVE-2026-58014

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-58014

Key Details

CVECVE-2026-58014
CVSS Score / Version7.3 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is low; integrity impact is low; availability impact is low.
Affected productssee table below
Classified asCWE-193 (Off-by-one Error)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatEnterprise Linux
Red HatRed Hat OpenShift AI 3.4
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red HatRed Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
Red HatRed Hat OpenShift AI 3.5
Red HatRed Hat Update Infrastructure 5
Red HatRed Hat OpenShift Container Platform 4.12
Red HatRed Hat OpenShift Container Platform 4.17
Red HatRed Hat OpenShift Container Platform 4.22
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support
Red HatRed Hat Enterprise Linux 6
Red HatCert Manager support for Red Hat OpenShift release 1.20
Red HatRed Hat AI Inference Server 3.2
Red HatRed Hat Discovery 2
Red HatRed Hat OpenShift AI 3.0
Red HatRed Hat OpenShift AI 3.2
GNOMEglib
Red HatCert Manager support for Red Hat OpenShift release 1.19
SubsystemsEWS Workstation Delivery/Virtualization
SectorsAll Sectors

What to Know

A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary. (NVD)

What to Do

Monitor Red Hat's and GNOME's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-58014
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-58014
Vendor advisoryhttps://access.redhat.com/security/cve/CVE-2026-58014