Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-81435.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-81435
Upstream
  • CVE-2026-5201
Published
2026-03-31T09:16:23Z
Modified
2026-09-01T05:28:09Z
Summary
CVE-2026-5201 affecting package gdk-pixbuf2 for versions less than 2.42.10-5
Details

A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.

References

Affected packages

Azure Linux:3 / gdk-pixbuf2

Package

Name
gdk-pixbuf2
Purl
pkg:rpm/azure-linux/gdk-pixbuf2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.42.10-5

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-81435.json"