Skip to content

CVE-2026-16118 (HIGH): detected in Lambda Docker Images. #650

Description

@the-lambda-watchdog

CVE Details

CVE ID Severity Affected Package Installed Version Fixed Version Date Published Date of Scan
CVE-2026-16118 HIGH glib2 2.82.2-770.amzn2023 2.82.2-771.amzn2023 2026-07-17T20:17:16.167Z 2026-08-05T10:18:12.738126749Z

Affected Docker Images

Image Name SHA
public.ecr.aws/lambda/provided:latest public.ecr.aws/lambda/provided@sha256:aa5e0a1b77749a4108e9664cbd385018afcaf7ad1a941687c3b47b943ef6ed70
public.ecr.aws/lambda/provided:al2023 public.ecr.aws/lambda/provided@sha256:aa5e0a1b77749a4108e9664cbd385018afcaf7ad1a941687c3b47b943ef6ed70
public.ecr.aws/lambda/python:latest public.ecr.aws/lambda/python@sha256:b159321dab22887313f1020bee51c7d42b963bd897999c4921dfc283bd7c9c53
public.ecr.aws/lambda/python:3.14 public.ecr.aws/lambda/python@sha256:b159321dab22887313f1020bee51c7d42b963bd897999c4921dfc283bd7c9c53
public.ecr.aws/lambda/python:3.13 public.ecr.aws/lambda/python@sha256:70e1683986413e2fbdfc8765950d2ef7aaa21a2239726389f92ace0d02fd281c
public.ecr.aws/lambda/python:3.12 public.ecr.aws/lambda/python@sha256:8fb317f01fddcbdcff73205b4a7a3f8faf4580fb56f9582e16f2396ccc24686e
public.ecr.aws/lambda/python:3.11 public.ecr.aws/lambda/python@sha256:2cd098e62931126b4834ce5b519dce07473cb60d290331307bd3b3061ed10e14
public.ecr.aws/lambda/python:3.10 public.ecr.aws/lambda/python@sha256:36ba855f52f7aaced0eda9a2648db2d6250cfc25ebad5cb5503d0a4acccbdfa2
public.ecr.aws/lambda/nodejs:latest public.ecr.aws/lambda/nodejs@sha256:f482802556ae1ae4b48af2b5548eb425410cccfa77f88776053942de7089262c
public.ecr.aws/lambda/nodejs:24 public.ecr.aws/lambda/nodejs@sha256:f482802556ae1ae4b48af2b5548eb425410cccfa77f88776053942de7089262c
public.ecr.aws/lambda/nodejs:22 public.ecr.aws/lambda/nodejs@sha256:4782203f949dbbf6bdec08a3a91614b2ba0661a74aa99171268856e75fd651c3
public.ecr.aws/lambda/java:latest public.ecr.aws/lambda/java@sha256:ab272aa801d4a026165442afdab9286812982188b4460e8d427abd746b392e60
public.ecr.aws/lambda/java:25 public.ecr.aws/lambda/java@sha256:ab272aa801d4a026165442afdab9286812982188b4460e8d427abd746b392e60
public.ecr.aws/lambda/java:21 public.ecr.aws/lambda/java@sha256:bb41505e5bd28b93e10183aa0fb6d18336c5d2e7966c0ad44ccbc3f29519e572
public.ecr.aws/lambda/java:17 public.ecr.aws/lambda/java@sha256:22c3790dc7f3a2ac2cf80062c834be5a8baf566cc07d3dc694f7fbdd37da2fda
public.ecr.aws/lambda/java:11 public.ecr.aws/lambda/java@sha256:513a29b61afb0806128198e934579905a217e47a103602f4af90bddf09727110
public.ecr.aws/lambda/java:8.al2 public.ecr.aws/lambda/java@sha256:dfd2ab121e072ce4ae867810ba810ebd73f78b0033ac153047b7904fd3fb1889
public.ecr.aws/lambda/dotnet:latest public.ecr.aws/lambda/dotnet@sha256:014f1fe947cf393a0d0a60bfc672da7ea886f68b053eab1b95eb29ca91bfea14
public.ecr.aws/lambda/dotnet:10 public.ecr.aws/lambda/dotnet@sha256:014f1fe947cf393a0d0a60bfc672da7ea886f68b053eab1b95eb29ca91bfea14
public.ecr.aws/lambda/dotnet:9 public.ecr.aws/lambda/dotnet@sha256:44917c069a1fb464c77508f5e37de5ad6d31c174277e25903153218d2dddf39e
public.ecr.aws/lambda/dotnet:8 public.ecr.aws/lambda/dotnet@sha256:e4724a3e1dc2d1577af202d3ccf6f3bd126b5b81950f80004d5f2c23bb06e514
public.ecr.aws/lambda/ruby:latest public.ecr.aws/lambda/ruby@sha256:fba89eabfed0ad818ed086dc49a69b3b519d54a51183725ade45e99344008d09
public.ecr.aws/lambda/ruby:4.0 public.ecr.aws/lambda/ruby@sha256:fba89eabfed0ad818ed086dc49a69b3b519d54a51183725ade45e99344008d09
public.ecr.aws/lambda/ruby:3.4 public.ecr.aws/lambda/ruby@sha256:cd5ca892a90185666607f50011260dc80f09691aee691d9dd31a99f17033ae55
public.ecr.aws/lambda/ruby:3.3 public.ecr.aws/lambda/ruby@sha256:373f8eaf1e4e32242231259de4de4e37fa40f6aa26efeaa50a14f6019b405e5b

Description

A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.


Remediation Steps

  • Update the affected package glib2 from version 2.82.2-770.amzn2023 to 2.82.2-771.amzn2023.

About this issue

  • This issue may not contain all the information about the CVE nor the images it affects.
  • This issue will not be updated with new information and the list of affected images may have changed since the creation of this issue.
  • For more, visit Lambda Watchdog.
  • This issue was created automatically by Lambda Watchdog.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions