Home

Description

A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.

PUBLISHED Reserved 2026-03-31 | Published 2026-03-31 | Updated 2026-05-21 | Assigner redhat




HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

Heap-based Buffer Overflow

Product status

Default status
affected

0:2.42.12-4.el10_1.5 (rpm) before *
unaffected

Default status
affected

0:2.42.12-4.el10_2.5 (rpm) before *
unaffected

Default status
affected

0:2.42.12-4.el10_0.4 (rpm) before *
unaffected

Default status
affected

0:2.36.12-5.el7_9 (rpm) before *
unaffected

Default status
affected

0:2.36.12-8.el8_10 (rpm) before *
unaffected

Default status
affected

0:2.36.12-8.el8_10 (rpm) before *
unaffected

Default status
affected

0:2.36.12-7.el8_2 (rpm) before *
unaffected

Default status
affected

0:2.36.12-7.el8_4 (rpm) before *
unaffected

Default status
affected

0:2.36.12-7.el8_4 (rpm) before *
unaffected

Default status
affected

0:2.36.12-7.el8_6 (rpm) before *
unaffected

Default status
affected

0:2.36.12-7.el8_6 (rpm) before *
unaffected

Default status
affected

0:2.36.12-7.el8_6 (rpm) before *
unaffected

Default status
affected

0:2.36.12-7.el8_8 (rpm) before *
unaffected

Default status
affected

0:2.36.12-7.el8_8 (rpm) before *
unaffected

Default status
affected

0:2.42.6-6.el9_7.1 (rpm) before *
unaffected

Default status
affected

0:2.42.6-6.el9_8.1 (rpm) before *
unaffected

Default status
affected

0:2.42.6-3.el9_0.1 (rpm) before *
unaffected

Default status
affected

0:2.42.6-4.el9_2.1 (rpm) before *
unaffected

Default status
affected

0:2.42.6-5.el9_4.1 (rpm) before *
unaffected

Default status
affected

0:2.42.6-6.el9_6.1 (rpm) before *
unaffected

Default status
affected

1779223654 (rpm) before *
unaffected

Default status
affected

1779223651 (rpm) before *
unaffected

Default status
affected

1778244559 (rpm) before *
unaffected

Default status
affected

1778244531 (rpm) before *
unaffected

Default status
affected

1778274666 (rpm) before *
unaffected

Default status
affected

1778244546 (rpm) before *
unaffected

Default status
unaffected

Default status
affected

Default status
unaffected

Default status
affected

Default status
unknown

Default status
unaffected

Timeline

2026-03-31:Reported to Red Hat.
2026-03-31:Made public.

Credits

Red Hat would like to thank Kağan Çapar for reporting this issue.

References

lists.debian.org/debian-lts-announce/2026/04/msg00010.html

access.redhat.com/errata/RHSA-2026:10707 (RHSA-2026:10707) vendor-advisory

access.redhat.com/errata/RHSA-2026:10708 (RHSA-2026:10708) vendor-advisory

access.redhat.com/errata/RHSA-2026:10741 (RHSA-2026:10741) vendor-advisory

access.redhat.com/errata/RHSA-2026:11325 (RHSA-2026:11325) vendor-advisory

access.redhat.com/errata/RHSA-2026:11326 (RHSA-2026:11326) vendor-advisory

access.redhat.com/errata/RHSA-2026:11327 (RHSA-2026:11327) vendor-advisory

access.redhat.com/errata/RHSA-2026:11328 (RHSA-2026:11328) vendor-advisory

access.redhat.com/errata/RHSA-2026:11806 (RHSA-2026:11806) vendor-advisory

access.redhat.com/errata/RHSA-2026:12060 (RHSA-2026:12060) vendor-advisory

access.redhat.com/errata/RHSA-2026:12061 (RHSA-2026:12061) vendor-advisory

access.redhat.com/errata/RHSA-2026:12062 (RHSA-2026:12062) vendor-advisory

access.redhat.com/errata/RHSA-2026:12114 (RHSA-2026:12114) vendor-advisory

access.redhat.com/errata/RHSA-2026:12115 (RHSA-2026:12115) vendor-advisory

access.redhat.com/errata/RHSA-2026:16008 (RHSA-2026:16008) vendor-advisory

access.redhat.com/errata/RHSA-2026:16009 (RHSA-2026:16009) vendor-advisory

access.redhat.com/errata/RHSA-2026:16030 (RHSA-2026:16030) vendor-advisory

access.redhat.com/errata/RHSA-2026:16174 (RHSA-2026:16174) vendor-advisory

access.redhat.com/errata/RHSA-2026:19127 (RHSA-2026:19127) vendor-advisory

access.redhat.com/errata/RHSA-2026:19210 (RHSA-2026:19210) vendor-advisory

access.redhat.com/errata/RHSA-2026:19724 (RHSA-2026:19724) vendor-advisory

access.redhat.com/errata/RHSA-2026:19725 (RHSA-2026:19725) vendor-advisory

access.redhat.com/security/cve/CVE-2026-5201 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2453291 (RHBZ#2453291) issue-tracking

gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/304

cve.org (CVE-2026-5201)

nvd.nist.gov (CVE-2026-5201)

Download JSON