CVE-2026-81893: Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recovery

Published Aug 27, 2026
·
Updated

A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image.

Affected version >= 2.26.4

Other sources

A flaw was found in gdk-pixbuf's JPEG loader (io-jpeg.c). When parsing chunked ICC profile data from JPEG APP2 markers, the error cleanup path in jpegparseexifapp2segment() frees the ICC profile buffer but previously failed to reset iccprofilesize and iccprofilesizeallocated. A specially crafted JPEG can trigger allocation, an error that frees the buffer while leaving stale size metadata, and a subsequent re-allocation that leads to an out-of-bounds write during ICC profile assembly.

The issue was introduced when error cleanup was added for chunked ICC profile handling in gdk-pixbuf 2.43.4/2.44.0 (commit 4af78023). It is fixed upstream in commit efe658674bd103d1c9bf50809d5767a3f6dd5a01 ("jpeg: When freeing memory, unset the size"), merged via https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/mergerequests/278 on 2026-08-24. No fixed upstream release tag exists yet.

Red Hat tracking: PSIRTSUPT-22558.

Red Hat

Affected Software

1 affected component
Gnome GDK-PixBuf>=undefined

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade gdk-pixbuf to a version that resolves this vulnerability.

    Patch efe658674bd103d1c9bf50809d5767a3f6dd5a01
  2. Compensating control

    Mitigate by preventing or limiting processing of untrusted/specially crafted JPEG images that trigger the gdk-pixbuf JPEG ICC profile parser error during decode.

Event History

Aug 27, 2026
Data Sourced
via Red Hat·06:08 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·06:34 PM
Data Sourced
via MITRE·06:34 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which applications are exposed to this issue?

Applications using gdk-pixbuf's JPEG loader are exposed when they process a specially crafted JPEG containing chunked ICC profile data. Exploitation requires local access and user interaction, as reflected by the AV:L and UI:R metrics.

2

Are all listed affected versions vulnerable?

The issue is listed as affecting versions 2.26.4 and later, but the vulnerable error-cleanup behavior was introduced in gdk-pixbuf 2.43.4/2.44.0. The provided data identifies upstream commit efe658674bd103d1c9bf50809d5767a3f6dd5a01 as the fix.

3

What is the expected impact of successful exploitation?

A crafted image can cause an out-of-bounds write during ICC profile assembly, potentially crashing the application. The supplied severity vector indicates no confidentiality or integrity impact and a high availability impact.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203