CVE-2026-91786

A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared dimensions against the actual data buffer size. A malicious or compromised remote search provider could exploit this by providing oversized icon dimensions, leading to an out-of-bounds read. This can cause the GNOME Shell process to crash, disrupting the user's session, and potentially disclose sensitive information from adjacent memory.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-15 11:17

Updated : 2026-09-15 14:17


NVD link : CVE-2026-91786

Mitre link : CVE-2026-91786

CVE.ORG link : CVE-2026-91786


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read