A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image.
Affected version >= 2.26.4
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81893.json",
"cwe_ids": [
"CWE-787"
],
"cna_assigner": "redhat"
}[
{
"id": "CVE-2026-81893-3a02400d",
"target": {
"function": "jpeg_parse_exif_app2_segment",
"file": "gdk-pixbuf/io-jpeg.c"
},
"deprecated": false,
"digest": {
"function_hash": "26746536089655105425758811082693675546",
"length": 1206.0
},
"signature_version": "v1",
"source": "https://gitlab.gnome.org/gnome/gdk-pixbuf@efe658674bd103d1c9bf50809d5767a3f6dd5a01",
"signature_type": "Function"
},
{
"id": "CVE-2026-81893-63073fe4",
"target": {
"file": "gdk-pixbuf/io-jpeg.c"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"84589065932154051515342609836841412127",
"339812710682483527173679640759887434893",
"142366550993056349944356857899954511914",
"96656125493800859959881939949970845351"
]
},
"signature_version": "v1",
"source": "https://gitlab.gnome.org/gnome/gdk-pixbuf@efe658674bd103d1c9bf50809d5767a3f6dd5a01",
"signature_type": "Line"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81893.json"
"2026-08-30T08:17:33Z"