Skip to content
Red HatCVE-2026-81893

Red Hat gdk-pixbuf.: out-of-bounds write

Medium4.7CVE-2026-81893 · Published Aug 27, 2026 · updated Aug 28, 2026

A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image. Affected version >= 2.26.4

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat rsyslog: buffer overflow
High7.5Aug 27
Red Hat Undertow. A remote attacker: resource exhaustion
High7.5Aug 27
Red Hat Satellite 6: insecure direct object reference
Medium6.5Aug 27
Red Hat Satellite 6: insecure direct object reference
Medium5.4Aug 27
A flaw was found in the ipa_getkeytab module of the community.general Ansible...
Medium5.5Aug 26
Red Hat Seattle FilmWorks plugin: integer overflow
Medium5.5Aug 26

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.