Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in GEGL's Radiance HDR (RGBE) image loader. rgbe_read_uncompressed() reads x_axis.size times 4 bytes from the memory-mapped file for every scanline and does not compare that length with the bytes remaining in the file. rgbe_rgbe_to_float() then loads those bytes. A crafted .hdr file whose declared image is larger than its scanline data can make the application that opens it crash. The pixel buffer is sized for the declared image, so this path is a read past the file mapping. It is distinct from the RLE output overflow tracked as CVE-2026-2050 and from the allocation overflow tracked as CVE-2026-18300: a height below the 32768-pixel cap still reaches the unbounded read.