Out-of-Bounds Read Vulnerability in GNOME Shell Affects System Stability
CVE-2026-91786

6.1MEDIUM

What is CVE-2026-91786?

A vulnerability exists in GNOME Shell due to inadequate validation of icon dimensions provided by remote search providers. When oversized dimensions are specified, the system may perform an out-of-bounds read, potentially leading to crashes in the GNOME Shell process. This flaw compromises user sessions and opens avenues for sensitive information to be exposed from adjacent memory locations, posing serious security risks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Mami for reporting this issue.
.