Affected version >= 2.26.4
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Avoid opening or automatically indexing untrusted JPEG images with applications linked against a vulnerable gdk-pixbuf version until an updated package is installed.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image. Affected version >= 2.26.4 | |
| Title | Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recovery | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
|
|
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-28T14:29:06.460Z
Reserved: 2026-08-27T18:05:10.048Z
Link: CVE-2026-81893
Updated: 2026-08-28T14:29:01.040Z
Status : Awaiting Analysis
Published: 2026-08-27T20:18:57.043
Modified: 2026-08-28T18:58:27.140
Link: CVE-2026-81893
OpenCVE Enrichment
Updated: 2026-08-28T09:15:05Z
-
CWE-787
Out-of-bounds Write