AZL-100929
Dashboard / Vulnerabilities / AZL-100929
Summary: CVE-2026-18090 affecting package gdk-pixbuf2 2.42.10-5
Details: A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.
References: https://nvd.nist.gov/vuln/detail/CVE-2026-18090
Affected packages
Package
Name: gdk-pixbuf2
Purl: pkg:rpm/azure-linux/gdk-pixbuf2
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
