Impact
The vulnerability in gdk-pixbuf centers on an out‑of‑bounds read in the uncompress() routine that handles RLE‑encoded ICNS data. A specially crafted Apple Icon Image file can cause the routine to read beyond the intended buffer, creating a potential denial‑of‑service when the application crashes or an information‑disclosure event if sensitive data is exposed from adjacent memory. The weakness is a classic case of heap corruption (CWE‑125).
Affected Systems
Affected platforms are Red Hat Enterprise Linux 6 through 10, as the gdk-pixbuf component shipped with those distributions contains the vulnerable code. All releases of the mentioned operating systems use gdk-pixbuf in the default graphics stack.
Risk and Exploitability
Assessment shows a CVSS score of 6.1, reflecting moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The attack requires delivery of a malicious ICNS file to an application that loads icons via gdk‑pixbuf, which is possible from remote file inclusion or local user interaction with untrusted files. Because the flaw leads to a crash or data exposure, the risk is significant if the affected image handling is invoked in privileged contexts. The official workaround advises disabling ICNS support or avoiding unknown sources until a patch is released.
OpenCVE Enrichment