CVE-2026-5201

A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
References
Link Resource
https://access.redhat.com/errata/RHSA-2026:10707 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:10708 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:10741 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:11325 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:11326 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:11327 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:11328 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:11806 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:12060 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:12061 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:12062 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:12114 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:12115 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:16008
https://access.redhat.com/errata/RHSA-2026:16009
https://access.redhat.com/errata/RHSA-2026:16030
https://access.redhat.com/errata/RHSA-2026:16174
https://access.redhat.com/errata/RHSA-2026:19127
https://access.redhat.com/errata/RHSA-2026:19210
https://access.redhat.com/errata/RHSA-2026:19724
https://access.redhat.com/errata/RHSA-2026:19725
https://access.redhat.com/errata/RHSA-2026:25096
https://access.redhat.com/security/cve/CVE-2026-5201 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2453291 Issue Tracking Third Party Advisory
https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/304 Issue Tracking Vendor Advisory
https://lists.debian.org/debian-lts-announce/2026/04/msg00010.html Mailing List Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:10707 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:10708 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:10741 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:11325 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:11326 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:11327 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:11328 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:11806 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:12060 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:12061 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:12062 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:12114 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:12115 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:16008
https://access.redhat.com/errata/RHSA-2026:16009
https://access.redhat.com/errata/RHSA-2026:16030
https://access.redhat.com/errata/RHSA-2026:16174
https://access.redhat.com/errata/RHSA-2026:19127
https://access.redhat.com/errata/RHSA-2026:19210
https://access.redhat.com/errata/RHSA-2026:19724
https://access.redhat.com/errata/RHSA-2026:19725
https://access.redhat.com/errata/RHSA-2026:25096
https://access.redhat.com/security/cve/CVE-2026-5201 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2453291 Issue Tracking Third Party Advisory
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5201.json
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnome:gdk-pixbuf:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.8:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-31 09:16

Updated : 2026-07-15 01:16


NVD link : CVE-2026-5201

Mitre link : CVE-2026-5201

CVE.ORG link : CVE-2026-5201


JSON object : View

Products Affected

gnome

  • gdk-pixbuf

redhat

  • enterprise_linux_server_tus
  • enterprise_linux
  • enterprise_linux_server_aus
CWE
CWE-122

Heap-based Buffer Overflow