在 gdk-pixbuf 中发现了一个缺陷。当加载一个经过特殊构造的、包含分块 ICC 配置文件标记的 JPEG 图像时,在 ICC 配置文件解析过程中发生的错误可能导致在配置文件缓冲区被释放后,仍然残留旧的尺寸元数据。随后的同一解码过程中的内存分配可能会引发越界写入,从而导致应用程序崩溃。要利用该缺陷,使用 gdk-pixbuf 的应用程序必须处理这个恶意的 JPEG 图像。 受影响的版本:≥ 2.26.4
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-5680 | 7.5 HIGH | Undertow-core: undertow: denial of service via websocket permessage-deflate processing |
| CVE-2026-78002 | 7.5 HIGH | Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() fun |
| CVE-2026-81658 | 6.5 MEDIUM | Foreman: cross-tenant disclosure of template revisions via unauthorized audit lookup |
| CVE-2026-80179 | 5.9 MEDIUM | Jwcrypto: jwcrypto: denial of service via malformed jwe tokens |
| CVE-2026-81668 | 5.4 MEDIUM | Rubygem-katello: cross-tenant content view filter rule access and modification via unautho |
No comments yet