云虫漏洞情报

CVE-2026-81893 - A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image. Affected version >= 2.26.4 - 漏洞详情

漏洞编号:CVE-2026-81893

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-81893

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-787

发布/更新时间:2026-08-27 / 2026-08-27

漏洞描述

A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image.

Affected version >= 2.26.4

相关链接

相关漏洞

« 返回首页