Bug 2544420 (CVE-2026-103641) - CVE-2026-103641 gegl: gegl04: gegl: out-of-bounds read in the Radiance HDR uncompressed scanline decoder
Summary: CVE-2026-103641 gegl: gegl04: gegl: out-of-bounds read in the Radiance HDR un...
Keywords:
Status: NEW
Alias: CVE-2026-103641
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2544422
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-01 03:27 UTC by OSIDB Bzimport
Modified: 2026-10-01 03:41 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-01 03:27:45 UTC
A flaw was found in GEGL's Radiance HDR (RGBE) image loader. rgbe_read_uncompressed() reads x_axis.size times 4 bytes from the memory-mapped file for every scanline and does not compare that length with the bytes remaining in the file. rgbe_rgbe_to_float() then loads those bytes. A crafted .hdr file whose declared image is larger than its scanline data can make the application that opens it crash. The pixel buffer is sized for the declared image, so this path is a read past the file mapping. It is distinct from the RLE output overflow tracked as CVE-2026-2050 and from the allocation overflow tracked as CVE-2026-18300: a height below the 32768-pixel cap still reaches the unbounded read.


Note You need to log in before you can comment on or make changes to this bug.