Out-of-Bounds Write Vulnerability in gdk-pixbuf Affects JPEG Image Processing
CVE-2026-81893

4.7MEDIUM

What is CVE-2026-81893?

A flaw in gdk-pixbuf allows processing of crafted JPEG images to result in mishandled ICC profile markers. This flaw can lead to an out-of-bounds write due to leftover size metadata after freeing the profile buffer, potentially crashing the application when attempting to allocate memory in the same decode context. Exploitation requires the application to process a malicious JPEG image.

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Emmanuele Bassi for reporting this issue.
.