CVE-2026-5201
published 2026-03-31CVE-2026-5201: A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.07%
61.1th percentile
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gdk-pixbuf | < gdk-pixbuf 2.44.6+dfsg-1 (forky) | gdk-pixbuf 2.44.6+dfsg-1 (forky) |
| gnome | gdk-pixbuf | >= 0 < 2.44.6+dfsg-1 | 2.44.6+dfsg-1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| ubuntu | gdk-pixbuf | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GDK-PixBuf vulnerability
vendor_ubuntu·2026-06-09
CVE-2026-5201 GDK-PixBuf vulnerability
Title: GDK-PixBuf vulnerability
Summary: GDK-PixBuf could be made to crash or run programs if it opened a specially
crafted file.
USN-8156-1 fixed a vulnerability in GDK-PixBuf. This update provides the
corresponding update for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
20.04 LTS.
Original advisory details:
It was discovered that GDK-PixBuf incorrectly handled certain JPEG files.
An attacker could use this issue to cause GDK-PixBuf to crash, resulting
in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GDK-PixBuf vulnerability
vendor_ubuntu·2026-04-08
CVE-2026-5201 GDK-PixBuf vulnerability
Title: GDK-PixBuf vulnerability
Summary: GDK-PixBuf could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that GDK-PixBuf incorrectly handled certain JPEG files.
An attacker could use this issue to cause GDK-PixBuf to crash, resulting in
a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image
vendor_redhat·2026-03-31·CVSS 7.5
CVE-2026-5201 [HIGH] CWE-122 gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image
gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this
Debian
CVE-2026-5201: gdk-pixbuf - A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vuln...
vendor_debian·2026·CVSS 7.5
CVE-2026-5201 [HIGH] CVE-2026-5201: gdk-pixbuf - A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vuln...
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.44.6+dfsg-1)
sid: resolved (fixed in 2.44.6+dfsg-1)
trixie: open
VulDB
gdk-pixbuf JPEG Image Loader heap-based overflow (EUVD-2026-17343 / Nessus ID 304410)
vuldb·2026-05-06·CVSS 7.5
CVE-2026-5201 [HIGH] gdk-pixbuf JPEG Image Loader heap-based overflow (EUVD-2026-17343 / Nessus ID 304410)
A vulnerability was found in gdk-pixbuf. It has been rated as critical. Affected by this issue is some unknown functionality of the component JPEG Image Loader. Performing a manipulation results in heap-based buffer overflow.
This vulnerability was named CVE-2026-5201. The attack may be initiated remotely. There is no available exploit.
OSV
CVE-2026-5201: A flaw was found in the gdk-pixbuf library
osv·2026-03-31·CVSS 7.5
CVE-2026-5201 [HIGH] CVE-2026-5201: A flaw was found in the gdk-pixbuf library
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
GHSA
GHSA-9pr2-m366-8728: A flaw was found in the gdk-pixbuf library
ghsa_unreviewed·2026-03-31
CVE-2026-5201 [HIGH] CWE-122 GHSA-9pr2-m366-8728: A flaw was found in the gdk-pixbuf library
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-5201 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-5201 [MEDIUM] CVE-2026-5201 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5201 :
Linux Debian vulnerability analysis and mitigation
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
Source : NVD
## 7.5
Score
Published March 31, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Debian
Linux Red Hat
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 30.6
Exploitation Probab
Bugzilla
CVE-2026-5201 gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image
bugzilla·2026-03-31·CVSS 7.5
CVE-2026-5201 [HIGH] CVE-2026-5201 gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image
CVE-2026-5201 gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image
Heap-Based Buffer Overflow vulnerability in the JPEG image loader of the gdk-pixbuf library. The flaw is caused by improper validation of color component counts in the gdk_pixbuf__jpeg_image_load() function, leading to insufficient memory allocation for pixel data. When a specially crafted JPEG image is processed, libjpeg writes more data than allocated, resulting in a heap buffer overflow. This can be triggered automatically via thumbnail generation without user interaction, causing application crashes and denial-of-service conditions. Claims of code execution are not reliably substantiated and require unrealistic conditions; however, the memory corruption
Bugzilla
CVE-2025-5201 assimp: Open Asset Import Library Assimp LWOLoader.cpp CountVertsAndFacesLWO2 out-of-bounds [fedora-42]
bugzilla·2025-05-29·CVSS 4.8
CVE-2025-5201 [MEDIUM] CVE-2025-5201 assimp: Open Asset Import Library Assimp LWOLoader.cpp CountVertsAndFacesLWO2 out-of-bounds [fedora-42]
CVE-2025-5201 assimp: Open Asset Import Library Assimp LWOLoader.cpp CountVertsAndFacesLWO2 out-of-bounds [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2369039
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains op
https://access.redhat.com/errata/RHSA-2026:10707https://access.redhat.com/errata/RHSA-2026:10708https://access.redhat.com/errata/RHSA-2026:10741https://access.redhat.com/errata/RHSA-2026:11325https://access.redhat.com/errata/RHSA-2026:11326https://access.redhat.com/errata/RHSA-2026:11327https://access.redhat.com/errata/RHSA-2026:11328https://access.redhat.com/errata/RHSA-2026:11806https://access.redhat.com/errata/RHSA-2026:12060https://access.redhat.com/errata/RHSA-2026:12061https://access.redhat.com/errata/RHSA-2026:12062https://access.redhat.com/errata/RHSA-2026:12114https://access.redhat.com/errata/RHSA-2026:12115https://access.redhat.com/errata/RHSA-2026:16008https://access.redhat.com/errata/RHSA-2026:16009https://access.redhat.com/errata/RHSA-2026:16030https://access.redhat.com/errata/RHSA-2026:16174https://access.redhat.com/errata/RHSA-2026:19127https://access.redhat.com/errata/RHSA-2026:19210https://access.redhat.com/errata/RHSA-2026:19724https://access.redhat.com/errata/RHSA-2026:19725https://access.redhat.com/errata/RHSA-2026:25096https://access.redhat.com/security/cve/CVE-2026-5201https://bugzilla.redhat.com/show_bug.cgi?id=2453291https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/304https://lists.debian.org/debian-lts-announce/2026/04/msg00010.htmlhttps://access.redhat.com/errata/RHSA-2026:10707https://access.redhat.com/errata/RHSA-2026:10708https://access.redhat.com/errata/RHSA-2026:10741https://access.redhat.com/errata/RHSA-2026:11325https://access.redhat.com/errata/RHSA-2026:11326https://access.redhat.com/errata/RHSA-2026:11327https://access.redhat.com/errata/RHSA-2026:11328https://access.redhat.com/errata/RHSA-2026:11806https://access.redhat.com/errata/RHSA-2026:12060https://access.redhat.com/errata/RHSA-2026:12061https://access.redhat.com/errata/RHSA-2026:12062https://access.redhat.com/errata/RHSA-2026:12114https://access.redhat.com/errata/RHSA-2026:12115https://access.redhat.com/errata/RHSA-2026:16008https://access.redhat.com/errata/RHSA-2026:16009https://access.redhat.com/errata/RHSA-2026:16030https://access.redhat.com/errata/RHSA-2026:16174https://access.redhat.com/errata/RHSA-2026:19127https://access.redhat.com/errata/RHSA-2026:19210https://access.redhat.com/errata/RHSA-2026:19724https://access.redhat.com/errata/RHSA-2026:19725https://access.redhat.com/errata/RHSA-2026:25096https://access.redhat.com/security/cve/CVE-2026-5201https://bugzilla.redhat.com/show_bug.cgi?id=2453291https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5201.json
2026-03-31
Published