CVE-2026-5201
Summary
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
Impact & exploitability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Additional information
- NVD record
- https://access.redhat.com/errata/RHSA-2026:10707Advisory
- https://access.redhat.com/errata/RHSA-2026:10708Advisory
- https://access.redhat.com/errata/RHSA-2026:10741Advisory
- https://access.redhat.com/errata/RHSA-2026:11325Advisory
- https://access.redhat.com/errata/RHSA-2026:11326Advisory
- https://access.redhat.com/errata/RHSA-2026:11327Advisory
- https://access.redhat.com/errata/RHSA-2026:11328Advisory
- https://access.redhat.com/errata/RHSA-2026:11806Advisory