Description
A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.
Published: 2026-09-08
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service or Information Disclosure via heap out‑of‑bounds read
Action: Apply Patch
AI Analysis

Impact

The vulnerability in gdk-pixbuf centers on an out‑of‑bounds read in the uncompress() routine that handles RLE‑encoded ICNS data. A specially crafted Apple Icon Image file can cause the routine to read beyond the intended buffer, creating a potential denial‑of‑service when the application crashes or an information‑disclosure event if sensitive data is exposed from adjacent memory. The weakness is a classic case of heap corruption (CWE‑125).

Affected Systems

Affected platforms are Red Hat Enterprise Linux 6 through 10, as the gdk-pixbuf component shipped with those distributions contains the vulnerable code. All releases of the mentioned operating systems use gdk-pixbuf in the default graphics stack.

Risk and Exploitability

Assessment shows a CVSS score of 6.1, reflecting moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The attack requires delivery of a malicious ICNS file to an application that loads icons via gdk‑pixbuf, which is possible from remote file inclusion or local user interaction with untrusted files. Because the flaw leads to a crash or data exposure, the risk is significant if the affected image handling is invoked in privileged contexts. The official workaround advises disabling ICNS support or avoiding unknown sources until a patch is released.

Generated by OpenCVE AI on September 9, 2026 at 08:34 UTC.

Remediation

Vendor Workaround

Do not open untrusted ICNS files from unknown sources. Disable ICNS image format support if not required.


OpenCVE Recommended Actions

  • Install the vendor‑issued patch for gdk‑pixbuf that corrects the bounds check in uncompress().
  • If a patch is not yet available, disable ICNS image format support in gdk‑pixbuf or through the application configuration.
  • Restrict viewing of .icns files to trusted sources only, and avoid opening files from unknown origins.

Generated by OpenCVE AI on September 9, 2026 at 08:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.
Title Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle block
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-125
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-14T12:08:21.333Z

Reserved: 2026-07-28T16:27:44.909Z

Link: CVE-2026-18090

cve-icon Vulnrichment

Updated: 2026-09-14T12:08:16.729Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T23:17:22.760

Modified: 2026-09-14T13:17:35.263

Link: CVE-2026-18090

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T08:45:07Z

Weaknesses