CVE-2026-5201: Gnome Gdk-Pixbuf
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
Affected products
- Gnome Gdk-Pixbuf: affected versions not specified
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only; version 9.0 only; version 10.0 only
- Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only
- Red Hat Enterprise Linux Server Tus: version 8.8 only
Published 2026-03-31. Last modified 2026-07-15.