CVE-2016-5116: Debian Linux

Critical severity, CVSS 9.1. EPSS: 3.8% chance of exploitation in the next 30 days.

gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memory or cause a denial of service (stack-based buffer under-read and application crash) via a long name.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Libgd Libgd: up to and including 2.2.1
  • Opensuse Leap: version 42.1 only

Published 2016-08-07. Last modified 2026-06-17.