Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-91786— Gnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer size

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GNOME Shell 中存在一个缺陷。在通过 D-Bus 处理来自远程搜索提供程序的图标时,系统未能验证图标声明的尺寸与实际数据缓冲区大小是否匹配。恶意或已失陷的远程搜索提供程序可以通过提供尺寸过大的图标尺寸来利用此漏洞,从而导致越界读取。这可能引发 GNOME Shell 进程崩溃,中断用户的会话,并可能泄露相邻内存中的敏感信息。

CVSS 6.1 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-91786

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Gnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer size
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared dimensions against the actual data buffer size. A malicious or compromised remote search provider could exploit this by providing oversized icon dimensions, leading to an out-of-bounds read. This can cause the GNOME Shell process to crash, disrupting the user's session, and potentially disclose sensitive information from adjacent memory.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-91786

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-91786

登录查看更多情报信息。

Vendor Advisories for CVE-2026-91786 (1)

Other References for CVE-2026-91786 (1)

Other References for CVE-2026-91786 (1)

Same Patch Batch · Red Hat · 2026-09-15 · 5 CVEs total

CVE-2026-75092 7.3 HIGH Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld
CVE-2026-81303 6.3 MEDIUM Hawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routehostnam
CVE-2026-81320 5.5 MEDIUM Hawtio-operator: hawtio-operator: tls private key written to operator log at debug level
CVE-2026-91926 3.7 LOW Gss-ntlmssp: gss-ntlmssp: memory leak in ntlm_decode_target_info via duplicated av_pair en

IV. Related Vulnerabilities

V. Comments for CVE-2026-91786

No comments yet


Leave a comment