Red HatCVE-2026-16768
Red Hat gdk-pixbuf.: out-of-bounds read
Medium5.3CVE-2026-16768 · Published Jul 23, 2026 · updated Jul 31, 2026
A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 6 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
| gdk-pixbuf Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-125
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 23 | Red Hat Certificate System 9: resource leak | Medium5.3 | No fix yet |
| Jul 23 | Red Hat odh-dashboard: authentication bypass | High8.8 | No fix yet |
| Jul 23 | Red Hat libcupsfilters: infinite loop | High7.5 | No fix yet |
| Jul 23 | Red Hat GNU nano: information disclosure | Medium6.8 | No fix yet |
| Jul 22 | Red Hat librest: attacker could bypass PKCE protections | Medium6.8 | No fix yet |
| Jul 22 | Red Hat Directory Server 11: denial of service | Medium5.3 | No fix yet |