Out-of-Bounds Read Vulnerability in GNOME Shell Affects System Stability
CVE-2026-91786
6.1MEDIUM
What is CVE-2026-91786?
A vulnerability exists in GNOME Shell due to inadequate validation of icon dimensions provided by remote search providers. When oversized dimensions are specified, the system may perform an out-of-bounds read, potentially leading to crashes in the GNOME Shell process. This flaw compromises user sessions and opens avenues for sensitive information to be exposed from adjacent memory locations, posing serious security risks.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Mami for reporting this issue.