Impact
A flaw in GNOME Shell allows an attacker who controls a remote search provider to send icon dimensions larger than the actual data buffer. The missing validation of the declared dimensions causes an out‑of‑bounds read, which can crash the GNOME Shell process, disrupt the user session, and potentially expose information stored in adjacent memory.
Affected Systems
The vulnerability affects GNOME Shell as delivered with Red Hat Enterprise Linux 10, 7, 8, and 9. No specific component versions beyond the default GNOME Shell bundled with these operating systems are listed as impacted.
Risk and Exploitability
The CVSS score is 6.1, indicating a medium severity issue. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting that wide‑scale exploitation has not been observed. The likely attack vector involves a malicious or compromised remote search provider supplying oversized icon data via D is known, the medium severity and the potential for memory disclosure warrant monitoring for any new advisories or updates.
OpenCVE Enrichment