Gdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image
Published Mar 31, 2026
7.5
HIGHCVSS 3.1
EPSS 1.22%
Description
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | affected |
|
- n/a
- 7.0
- 8.0
- 9.0
- 10.0
- 8.2
- 8.4
- 8.8
No data.
Red Hat AI Inference Server 3.2
rhaiis/model-opt-cuda-rhel9:1780681984
Fixed · RHSA-2026:25096
Red Hat AI Inference Server 3.2
rhaiis/vllm-cuda-rhel9:1779223654
Fixed · RHSA-2026:19724
Red Hat AI Inference Server 3.2
rhaiis/vllm-rocm-rhel9:1779223651
Fixed · RHSA-2026:19725
Red Hat AI Inference Server 3.3
rhaiis/model-opt-cuda-rhel9:1778244559
Fixed · RHSA-2026:16008
Red Hat AI Inference Server 3.3
rhaiis/vllm-cuda-rhel9:1778274666
Fixed · RHSA-2026:16030
Red Hat AI Inference Server 3.3
rhaiis/vllm-rocm-rhel9:1778244531
Fixed · RHSA-2026:16009
Red Hat AI Inference Server 3.3
rhaiis/vllm-spyre-rhel9:1778244546
Fixed · RHSA-2026:16174
Red Hat Enterprise Linux 10
gdk-pixbuf2-0:2.42.12-4.el10_1.5
Fixed · RHSA-2026:10707
Red Hat Enterprise Linux 10
gdk-pixbuf2-0:2.42.12-4.el10_2.5
Fixed · RHSA-2026:19127
Red Hat Enterprise Linux 10.0 Extended Update Support
gdk-pixbuf2-0:2.42.12-4.el10_0.4
Fixed · RHSA-2026:11325
Red Hat Enterprise Linux 7 Extended Lifecycle Support
gdk-pixbuf2-0:2.36.12-5.el7_9
Fixed · RHSA-2026:12114
Red Hat Enterprise Linux 8
gdk-pixbuf2-0:2.36.12-8.el8_10
Fixed · RHSA-2026:10741
Red Hat Enterprise Linux 8
gdk-pixbuf2-0:2.36.12-8.el8_10
Fixed · RHSA-2026:10741
Red Hat Enterprise Linux 8.2 Advanced Update Support
gdk-pixbuf2-0:2.36.12-7.el8_2
Fixed · RHSA-2026:11806
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
gdk-pixbuf2-0:2.36.12-7.el8_4
Fixed · RHSA-2026:12062
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
gdk-pixbuf2-0:2.36.12-7.el8_4
Fixed · RHSA-2026:12062
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
gdk-pixbuf2-0:2.36.12-7.el8_6
Fixed · RHSA-2026:12115
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
gdk-pixbuf2-0:2.36.12-7.el8_6
Fixed · RHSA-2026:12115
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
gdk-pixbuf2-0:2.36.12-7.el8_6
Fixed · RHSA-2026:12115
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
gdk-pixbuf2-0:2.36.12-7.el8_8
Fixed · RHSA-2026:12060
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
gdk-pixbuf2-0:2.36.12-7.el8_8
Fixed · RHSA-2026:12060
Red Hat Enterprise Linux 9
gdk-pixbuf2-0:2.42.6-6.el9_7.1
Fixed · RHSA-2026:10708
Red Hat Enterprise Linux 9
gdk-pixbuf2-0:2.42.6-6.el9_8.1
Fixed · RHSA-2026:19210
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
gdk-pixbuf2-0:2.42.6-3.el9_0.1
Fixed · RHSA-2026:12061
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
gdk-pixbuf2-0:2.42.6-4.el9_2.1
Fixed · RHSA-2026:11326
Red Hat Enterprise Linux 9.4 Extended Update Support
gdk-pixbuf2-0:2.42.6-5.el9_4.1
Fixed · RHSA-2026:11328
Red Hat Enterprise Linux 9.6 Extended Update Support
gdk-pixbuf2-0:2.42.6-6.el9_6.1
Fixed · RHSA-2026:11327
Red Hat Enterprise Linux 10
glycin-loaders
Not affected
Red Hat Enterprise Linux 10
loupe
Affected
Red Hat Enterprise Linux 10
papers
Not affected
Red Hat Enterprise Linux 10
snapshot
Affected
Red Hat Enterprise Linux 6
gdk-pixbuf2
Out of support scope
Red Hat Enterprise Linux 9
librsvg2
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AI Inference Server 3.2 | rhaiis/model-opt-cuda-rhel9:1780681984 | Fixed | RHSA-2026:25096 |
| Red Hat AI Inference Server 3.2 | rhaiis/vllm-cuda-rhel9:1779223654 | Fixed | RHSA-2026:19724 |
| Red Hat AI Inference Server 3.2 | rhaiis/vllm-rocm-rhel9:1779223651 | Fixed | RHSA-2026:19725 |
| Red Hat AI Inference Server 3.3 | rhaiis/model-opt-cuda-rhel9:1778244559 | Fixed | RHSA-2026:16008 |
| Red Hat AI Inference Server 3.3 | rhaiis/vllm-cuda-rhel9:1778274666 | Fixed | RHSA-2026:16030 |
| Red Hat AI Inference Server 3.3 | rhaiis/vllm-rocm-rhel9:1778244531 | Fixed | RHSA-2026:16009 |
| Red Hat AI Inference Server 3.3 | rhaiis/vllm-spyre-rhel9:1778244546 | Fixed | RHSA-2026:16174 |
| Red Hat Enterprise Linux 10 | gdk-pixbuf2-0:2.42.12-4.el10_1.5 | Fixed | RHSA-2026:10707 |
| Red Hat Enterprise Linux 10 | gdk-pixbuf2-0:2.42.12-4.el10_2.5 | Fixed | RHSA-2026:19127 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | gdk-pixbuf2-0:2.42.12-4.el10_0.4 | Fixed | RHSA-2026:11325 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | gdk-pixbuf2-0:2.36.12-5.el7_9 | Fixed | RHSA-2026:12114 |
| Red Hat Enterprise Linux 8 | gdk-pixbuf2-0:2.36.12-8.el8_10 | Fixed | RHSA-2026:10741 |
| Red Hat Enterprise Linux 8 | gdk-pixbuf2-0:2.36.12-8.el8_10 | Fixed | RHSA-2026:10741 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | gdk-pixbuf2-0:2.36.12-7.el8_2 | Fixed | RHSA-2026:11806 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | gdk-pixbuf2-0:2.36.12-7.el8_4 | Fixed | RHSA-2026:12062 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | gdk-pixbuf2-0:2.36.12-7.el8_4 | Fixed | RHSA-2026:12062 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | gdk-pixbuf2-0:2.36.12-7.el8_6 | Fixed | RHSA-2026:12115 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | gdk-pixbuf2-0:2.36.12-7.el8_6 | Fixed | RHSA-2026:12115 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | gdk-pixbuf2-0:2.36.12-7.el8_6 | Fixed | RHSA-2026:12115 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | gdk-pixbuf2-0:2.36.12-7.el8_8 | Fixed | RHSA-2026:12060 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | gdk-pixbuf2-0:2.36.12-7.el8_8 | Fixed | RHSA-2026:12060 |
| Red Hat Enterprise Linux 9 | gdk-pixbuf2-0:2.42.6-6.el9_7.1 | Fixed | RHSA-2026:10708 |
| Red Hat Enterprise Linux 9 | gdk-pixbuf2-0:2.42.6-6.el9_8.1 | Fixed | RHSA-2026:19210 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | gdk-pixbuf2-0:2.42.6-3.el9_0.1 | Fixed | RHSA-2026:12061 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | gdk-pixbuf2-0:2.42.6-4.el9_2.1 | Fixed | RHSA-2026:11326 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | gdk-pixbuf2-0:2.42.6-5.el9_4.1 | Fixed | RHSA-2026:11328 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | gdk-pixbuf2-0:2.42.6-6.el9_6.1 | Fixed | RHSA-2026:11327 |
| Red Hat Enterprise Linux 10 | glycin-loaders | Not affected | n/a |
| Red Hat Enterprise Linux 10 | loupe | Affected | n/a |
| Red Hat Enterprise Linux 10 | papers | Not affected | n/a |
| Red Hat Enterprise Linux 10 | snapshot | Affected | n/a |
| Red Hat Enterprise Linux 6 | gdk-pixbuf2 | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | librsvg2 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
To reduce the risk of exploitation, avoid opening or processing untrusted JPEG image files. This operational control helps prevent the automatic triggering of the vulnerability, for example, during thumbnail generation, which could otherwise lead to application instability.
Red Hat statement
An Important heap-based buffer overflow flaw exists in the `gdk-pixbuf` library's JPEG image loader. This vulnerability can be triggered automatically without user interaction when processing a specially crafted JPEG image, such as during thumbnail generation. Successful exploitation leads to application crashes and denial-of-service conditions in applications utilizing `gdk-pixbuf` for image handling.
Red Hat mitigation
To reduce the risk of exploitation, avoid opening or processing untrusted JPEG image files. This operational control helps prevent the automatic triggering of the vulnerability, for example, during thumbnail generation, which could otherwise lead to application instability.
References (29)
- https://access.redhat.com/errata/RHSA-2026:10707 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:10708 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:10741 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:11325 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:11326 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:11327 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:11328 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:11806 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:12060 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:12061 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:12062 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:12114 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:12115 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2026:16008 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:16009 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:16030 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:16174 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:19127 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:19210 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:19724 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:19725 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:25096 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-5201 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2453291 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/304 Issue TrackingVendor Advisory
- https://lists.debian.org/debian-lts-announce/2026/04/msg00010.html Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-5201
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5201.json
- https://www.cve.org/CVERecord?id=CVE-2026-5201
Change history (0)
No recorded changes yet.