Memory Corruption Flaw in GEGL's Radiance HDR Loader Affects Multiple Applications
CVE-2026-103641
5.5MEDIUM
What is CVE-2026-103641?
A flaw exists in the Radiance HDR loader component of GEGL that allows for improper handling of memory when processing crafted HDR files. Specifically, the loader reads beyond the allocated memory bounds when an uncompressed scanline is shorter than the width specified in the file header. This can lead to application crashes for any software utilizing this loader, creating significant disruption and potential data loss.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Glops Elemiu for reporting this issue.