Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81893— Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recovery

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 gdk-pixbuf 中发现了一个缺陷。当加载一个经过特殊构造的、包含分块 ICC 配置文件标记的 JPEG 图像时,在 ICC 配置文件解析过程中发生的错误可能导致在配置文件缓冲区被释放后,仍然残留旧的尺寸元数据。随后的同一解码过程中的内存分配可能会引发越界写入,从而导致应用程序崩溃。要利用该缺陷,使用 gdk-pixbuf 的应用程序必须处理这个恶意的 JPEG 图像。 受影响的版本:≥ 2.26.4

CVSS 4.7 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81893

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recovery
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image. Affected version >= 2.26.4
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-81893

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81893

登录查看更多情报信息。

Patches & Fixes for CVE-2026-81893 (2)

Vendor Advisories for CVE-2026-81893 (1)

Other References for CVE-2026-81893 (1)

Same Patch Batch · Red Hat · 2026-08-27 · 6 CVEs total

CVE-2026-5680 7.5 HIGH Undertow-core: undertow: denial of service via websocket permessage-deflate processing
CVE-2026-78002 7.5 HIGH Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() fun
CVE-2026-81658 6.5 MEDIUM Foreman: cross-tenant disclosure of template revisions via unauthorized audit lookup
CVE-2026-80179 5.9 MEDIUM Jwcrypto: jwcrypto: denial of service via malformed jwe tokens
CVE-2026-81668 5.4 MEDIUM Rubygem-katello: cross-tenant content view filter rule access and modification via unautho

IV. Related Vulnerabilities

V. Comments for CVE-2026-81893

No comments yet


Leave a comment