Double Free Vulnerability in Nothings stb Multi-frame GIF File Handler
CVE-2026-5186

4.8MEDIUM

Key Information:

Vendor

Nothings

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-5186?

A vulnerability has been discovered in Nothings stb, particularly within the Multi-frame GIF File Handler implemented in stb_image.h. This flaw stems from an improper handling of memory that can lead to a double free condition during the execution of the function stbi__load_gif_main. Exploiting this vulnerability necessitates local access and could potentially be leveraged for attacks, given that proof-of-concept exploit code has already been made publicly available. Despite early notification to the vendor regarding this issue, no response has been received.

Affected Version(s)

stb 2.0

stb 2.1

stb 2.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

d0razi (VulDB User)
VulDB
.