DEBIAN-CVE-2026-18090
Dashboard / Vulnerabilities / DEBIAN-CVE-2026-18090
Summary:
Details: A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.
Affected packages
Package
Name: gdk-pixbuf
Purl: pkg:deb/debian/gdk-pixbuf?arch=source&distro=bookworm
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
Affected versions
2.42.10+dfsg-1
2.42.10+dfsg-1+deb12u1
2.42.10+dfsg-1+deb12u2
2.42.10+dfsg-1+deb12u3
2.42.10+dfsg-1+deb12u4
2.42.10+dfsg-2
2.42.10+dfsg-3
2.42.12+dfsg-1
2.42.12+dfsg-2
2.42.12+dfsg-3
2.42.12+dfsg-4
2.42.12+dfsg-5
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
