Out-of-Bounds Read Vulnerability in GDK-Pixbuf Affects Red Hat Products
CVE-2026-16768

5.3MEDIUM

What is CVE-2026-16768?

A security flaw exists in GDK-Pixbuf that can be exploited when parsing specifically crafted ICO files. This defect arises from inadequate bounds checking related to the defined palette size, which can result in an out-of-bounds read. Consequently, it allows an attacker to manipulate heap memory, causing valid palette indices to become misinterpreted. This vulnerability can lead to the unintentional exposure of sensitive heap contents, such as images or other data, through the generation of output images like thumbnails.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Matej Smycka for reporting this issue.
.