{"id":"AZL-98370","summary":"CVE-2026-81893 affecting package gdk-pixbuf2 2.42.10-5","details":"A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image.\n\nAffected version \u003e= 2.26.4","modified":"2026-09-03T05:27:10Z","published":"2026-08-27T20:18:57Z","upstream":["CVE-2026-81893"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81893"}],"affected":[{"package":{"name":"gdk-pixbuf2","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/gdk-pixbuf2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.42.10-5"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98370.json"}}],"schema_version":"1.9.0"}