Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16768

Опубликовано: 08 июн. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail.

Отчет

To exploit this flaw, an attacker must be able to process a specially crafted ICO file with an application linked to the gdk-pixbuf library. The only security impact of this issue is an information leak of memory contents via the generated output, such as a thumbnail. Also, the attacker does not have full control of the information obtained, further limiting its impact. Due to these reasons, this vulnerability has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this vulnerability, if the application does not require support for ICO files, disable the gdk-pixbuf ICO loader to prevent the vulnerable module from being executed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gdk-pixbuf2Fix deferred
Red Hat Enterprise Linux 6gdk-pixbuf2Fix deferred
Red Hat Enterprise Linux 7gdk-pixbuf2Fix deferred
Red Hat Enterprise Linux 8gdk-pixbuf2Fix deferred
Red Hat Enterprise Linux 9gdk-pixbuf2Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2506437gdk-pixbuf: out-of-bounds read in ICO parser

EPSS

Процентиль: 15%
0.00236
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
19 дней назад

A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail.

CVSS3: 5.3
nvd
19 дней назад

A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail.

msrc
16 дней назад

Gdk-pixbuf: out-of-bounds read in ico parser

CVSS3: 5.3
debian
19 дней назад

A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO f ...

CVSS3: 5.3
github
18 дней назад

A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail.

EPSS

Процентиль: 15%
0.00236
Низкий

5.3 Medium

CVSS3