REDHAT-BUG-2453291: Buffer Overflow
Published Mar 31, 2026
·Updated
Heap-Based Buffer Overflow vulnerability in the JPEG image loader of the gdk-pixbuf library. The flaw is caused by improper validation of color component counts in the gdkpixbufjpegimageload() function, leading to insufficient memory allocation for pixel data. When a specially crafted JPEG image is processed, libjpeg writes more data than allocated, resulting in a heap buffer overflow. This can be triggered automatically via thumbnail generation without user interaction, causing application crashes and denial-of-service conditions. Claims of code execution are not reliably substantiated and require unrealistic conditions; however, the memory corruption and crash impact are confirmed with high confidence.
Affected Software
1 affected component
Gnome GDK-PixBuf
Event History
Mar 31, 2026
Data Sourced
via Red Hat·07:23 AM
DescriptionSeverityAffected Software