{"id":"CVE-2026-81893","summary":"Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recovery","details":"A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image.\n\nAffected version \u003e= 2.26.4","modified":"2026-08-30T08:17:33.934208Z","published":"2026-08-27T18:34:03.016Z","database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81893.json"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-81893"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81893.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81893"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2524834"},{"type":"FIX","url":"https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/efe658674bd103d1c9bf50809d5767a3f6dd5a01"},{"type":"FIX","url":"https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/278"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.gnome.org/gnome/gdk-pixbuf","events":[{"introduced":"0"},{"fixed":"efe658674bd103d1c9bf50809d5767a3f6dd5a01"}],"database_specific":{"source":"REFERENCES"}}],"versions":["2.44.6","2.44.5","2.44.2","2.42.12","2.42.11","2.42.10","2.42.9","2.42.8","2.42.6","2.42.4","2.42.2","2.42.0","2.40.0","2.39.2","2.38.0","2.37.92","2.37.0","2.36.12","2.36.11","2.36.10","2.36.9","2.36.8","2.36.7","2.36.6","2.36.5","2.36.4","2.36.3","2.36.2","2.36.1","2.36.0","2.35.5","2.35.4","2.35.3","2.35.2","2.35.1","2.34.0","2.33.2","2.33.1","2.32.1","2.32.0","2.31.7","2.31.6","2.31.5","2.31.4","2.31.3","2.31.2","2.31.1","2.31.0","2.30.8","2.30.7","2.30.6","2.30.5","2.30.4","2.30.3","2.30.2","2.30.1","2.30.0","2.29.3","2.29.2","2.29.1","2.29.0","2.28.0","2.27.3","2.27.2","2.27.1","2.27.0","2.26.5","2.26.4","2.26.3","2.26.2","2.26.1","2.26.0","2.25.2","2.25.0","2.24.0","2.23.5","2.23.4","2.23.3","2.23.2","2.23.1","2.23.0","2.22.1","2.22.0","2.21.7","2.21.6","2.21.4","2.21.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81893.json","vanir_signatures_modified":"2026-08-30T08:17:33Z","vanir_signatures":[{"target":{"file":"gdk-pixbuf/io-jpeg.c","function":"jpeg_parse_exif_app2_segment"},"deprecated":false,"digest":{"function_hash":"26746536089655105425758811082693675546","length":1206},"id":"CVE-2026-81893-3a02400d","signature_type":"Function","signature_version":"v1","source":"https://gitlab.gnome.org/gnome/gdk-pixbuf@efe658674bd103d1c9bf50809d5767a3f6dd5a01"},{"signature_type":"Line","signature_version":"v1","source":"https://gitlab.gnome.org/gnome/gdk-pixbuf@efe658674bd103d1c9bf50809d5767a3f6dd5a01","target":{"file":"gdk-pixbuf/io-jpeg.c"},"deprecated":false,"digest":{"line_hashes":["84589065932154051515342609836841412127","339812710682483527173679640759887434893","142366550993056349944356857899954511914","96656125493800859959881939949970845351"],"threshold":0.9},"id":"CVE-2026-81893-63073fe4"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}