AZL-100929

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100929.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-100929
Upstream
  • CVE-2026-18090
Published
2026-09-08T23:17:22Z
Modified
2026-09-14T05:26:59Z
Summary
CVE-2026-18090 affecting package gdk-pixbuf2 2.42.10-5
Details

A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.

References

Affected packages

Azure Linux:3 / gdk-pixbuf2

Package

Name
gdk-pixbuf2
Purl
pkg:rpm/azure-linux/gdk-pixbuf2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.42.10-5

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100929.json"