Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20558-1

Опубликовано: 17 апр. 2026
Источник: suse-cvrf

Описание

Security update for gdk-pixbuf

This update for gdk-pixbuf fixes the following issue:

  • CVE-2026-5201: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image (bsc#1261210).

Список пакетов

openSUSE Leap 16.0
gdk-pixbuf-devel-2.42.12-160000.4.1
gdk-pixbuf-lang-2.42.12-160000.4.1
gdk-pixbuf-query-loaders-2.42.12-160000.4.1
gdk-pixbuf-thumbnailer-2.42.12-160000.4.1
libgdk_pixbuf-2_0-0-2.42.12-160000.4.1
typelib-1_0-GdkPixbuf-2_0-2.42.12-160000.4.1
typelib-1_0-GdkPixdata-2_0-2.42.12-160000.4.1

Описание

A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.


Затронутые продукты
openSUSE Leap 16.0:gdk-pixbuf-devel-2.42.12-160000.4.1
openSUSE Leap 16.0:gdk-pixbuf-lang-2.42.12-160000.4.1
openSUSE Leap 16.0:gdk-pixbuf-query-loaders-2.42.12-160000.4.1
openSUSE Leap 16.0:gdk-pixbuf-thumbnailer-2.42.12-160000.4.1

Ссылки