Bug 2453291 (CVE-2026-5201)

Summary: CVE-2026-5201 gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-03-31 07:23:34 UTC
Heap-Based Buffer Overflow vulnerability in the JPEG image loader of the gdk-pixbuf library. The flaw is caused by improper validation of color component counts in the gdk_pixbuf__jpeg_image_load() function, leading to insufficient memory allocation for pixel data. When a specially crafted JPEG image is processed, libjpeg writes more data than allocated, resulting in a heap buffer overflow. This can be triggered automatically via thumbnail generation without user interaction, causing application crashes and denial-of-service conditions. Claims of code execution are not reliably substantiated and require unrealistic conditions; however, the memory corruption and crash impact are confirmed with high confidence.

Comment 2 errata-xmlrpc 2026-04-27 01:34:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:10707 https://access.redhat.com/errata/RHSA-2026:10707

Comment 3 errata-xmlrpc 2026-04-27 02:01:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:10708 https://access.redhat.com/errata/RHSA-2026:10708

Comment 4 errata-xmlrpc 2026-04-27 09:06:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:10741 https://access.redhat.com/errata/RHSA-2026:10741

Comment 5 errata-xmlrpc 2026-04-28 06:57:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:11325 https://access.redhat.com/errata/RHSA-2026:11325

Comment 6 errata-xmlrpc 2026-04-28 07:03:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:11326 https://access.redhat.com/errata/RHSA-2026:11326

Comment 7 errata-xmlrpc 2026-04-28 07:07:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:11327 https://access.redhat.com/errata/RHSA-2026:11327

Comment 8 errata-xmlrpc 2026-04-28 07:12:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:11328 https://access.redhat.com/errata/RHSA-2026:11328

Comment 9 errata-xmlrpc 2026-04-29 15:43:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2026:11806 https://access.redhat.com/errata/RHSA-2026:11806

Comment 10 errata-xmlrpc 2026-04-30 04:47:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:12060 https://access.redhat.com/errata/RHSA-2026:12060

Comment 11 errata-xmlrpc 2026-04-30 04:52:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2026:12061 https://access.redhat.com/errata/RHSA-2026:12061

Comment 12 errata-xmlrpc 2026-04-30 04:56:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:12062 https://access.redhat.com/errata/RHSA-2026:12062

Comment 13 errata-xmlrpc 2026-04-30 07:02:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2026:12115 https://access.redhat.com/errata/RHSA-2026:12115

Comment 14 errata-xmlrpc 2026-04-30 07:02:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:12114 https://access.redhat.com/errata/RHSA-2026:12114

Comment 16 errata-xmlrpc 2026-05-19 16:05:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:19127 https://access.redhat.com/errata/RHSA-2026:19127

Comment 17 errata-xmlrpc 2026-05-19 18:02:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:19210 https://access.redhat.com/errata/RHSA-2026:19210