CVE-2026-107651: Eog: eog: arbitrary code execution via heap buffer overflow in png metadata reader
A flaw was found in Eye of GNOME (eog). A heap-based buffer overflow exists in the PNG metadata reader due to improper state handling when parsing split metadata chunks. A remote attacker could exploit this flaw by enticing a user into opening a specially crafted PNG file, potentially leading to arbitrary code execution or a Denial of Service (DoS) via application crash.
Other sources
A heap buffer overflow vulnerability was found in Eye of GNOME (eog) in the PNG metadata reader component (eog-metadata-reader-png). The flaw exists in the handling of cHRM and gAMA chunk resume state during PNG file parsing. An attacker could exploit this by crafting a malicious PNG file that, when opened by a victim, triggers the overflow, potentially leading to arbitrary code execution or a denial of service.
Upstream issue: https://gitlab.gnome.org/GNOME/eog/-/issues/342
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to trigger this issue?
The attacker must provide a specially crafted PNG file and persuade a user to open it in Eye of GNOME. The vulnerable parsing path involves split cHRM and gAMA metadata chunks.
Is user interaction required?
Yes. The issue is triggered when a victim opens the malicious PNG file, consistent with the UI:R vector.
What impact could exploitation have?
Exploitation may cause Eye of GNOME to crash, resulting in denial of service. The heap-based buffer overflow could also potentially lead to arbitrary code execution.