Описание
ELSA-2026-12114: gdk-pixbuf2 security update (IMPORTANT)
[2.36.12-3.0.3]
- Backport fixes for CVE-2026-5201 [Orabug: 39288631]
[2.36.12-3.0.1]
- jpeg: Be more careful with chunked icc data [Orabug: 38359772][CVE-2025-7345]
Обновленные пакеты
Oracle Linux 7
Oracle Linux x86_64
gdk-pixbuf2
2.36.12-3.0.3.el7
gdk-pixbuf2-devel
2.36.12-3.0.3.el7
gdk-pixbuf2-tests
2.36.12-3.0.3.el7
Связанные CVE
Связанные уязвимости
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
Gdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image
A flaw was found in the gdk-pixbuf library. This heap-based buffer ove ...