Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-9672

Опубликовано: 26 июл. 2026
Источник: redhat
CVSS3: 8.1

Описание

A flaw was found in libgd. Processing a specially crafted GIF file allows a remote attacker to trigger a buffer overflow, resulting in an application crash and a denial of service. Arbitrary code execution is possible in theory, but considered highly unlikely because standard image decompression and pixel manipulation generally destroy the exploit payload.

Отчет

To exploit this flaw, a remote attacker needs to be able to process a crafted GIF file with an application linked to the libgd library. Successful exploitation can result in an application crash, leading to a denial of service, or in arbitrary code execution. However, arbitrary code execution is highly unlikely because standard image decompression and pixel manipulation generally destroy the exploit payload. For these reasons, this vulnerability has been rated with an important severity. Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) memory protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gdAffected
Red Hat Enterprise Linux 10libwmfAffected
Red Hat Enterprise Linux 10nautilusAffected
Red Hat Enterprise Linux 10phpAffected
Red Hat Enterprise Linux 10php8.4Not affected
Red Hat Enterprise Linux 6gdAffected
Red Hat Enterprise Linux 6phpAffected
Red Hat Enterprise Linux 7gdAffected
Red Hat Enterprise Linux 7phpAffected
Red Hat Enterprise Linux 8gdAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2533111libgd: buffer overflow when processing specially crafted GIF file

8.1 High

CVSS3

Связанные уязвимости

ubuntu
около 2 месяцев назад

[Unknown description]

debian

Описание отсутствует

suse-cvrf
около 1 месяца назад

Security update for gd

suse-cvrf
около 1 месяца назад

Security update for gd

suse-cvrf
около 1 месяца назад

Security update for gd

8.1 High

CVSS3