Bug#1147444: gdk-pixbuf: CVE-2026-18090: out-of-bounds read when loading malicious .icns file

Simon McVittie smcv at debian.org
Sun Sep 13 13:51:08 BST 2026


Control: retitle -1 gdk-pixbuf: CVE-2026-18090: out-of-bounds read when loading malicious .icns file

On Fri, 11 Sep 2026 at 22:41:44 +0200, Moritz Mühlenhoff wrote:
>| This vulnerability allows a remote
>| attacker to cause a heap out-of-bounds read by providing a specially
>| crafted Apple Icon Image (.icns) file.

In testing/unstable, I believe this only affects -ports architectures: 
gdk-pixbuf >= 2.44.5+dfsg-3 loads most image formats using glycin rather 
than its own C code. (Exceptions: .xpm, .xbm still use C code because 
the equivalent Rust code in glycin was not feature-complete until 
recently.)

trixie is still affected. I am not aware of a patch being available.

     smcv



More information about the pkg-gnome-maintainers mailing list