DEBIAN-CVE-2026-91786

Source
https://security-tracker.debian.org/tracker/CVE-2026-91786
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-91786.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-91786
Upstream
  • CVE-2026-91786
Published
2026-09-15T11:17:12Z
Modified
2026-09-16T19:00:14Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared dimensions against the actual data buffer size. A malicious or compromised remote search provider could exploit this by providing oversized icon dimensions, leading to an out-of-bounds read. This can cause the GNOME Shell process to crash, disrupting the user's session, and potentially disclose sensitive information from adjacent memory.

References

Affected packages

Debian:12 / gnome-shell

Package

Name
gnome-shell
Purl
pkg:deb/debian/gnome-shell?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

43.*
43.4-1
43.6-1~deb12u1
43.6-1~deb12u2
43.6-1
43.7-1
43.7-2
43.9-0+deb12u1
43.9-0+deb12u2
Other
44~beta-1
44~rc-1
45~rc-1
47~beta-1
47~rc-1
47~rc-3
48~beta-1
48~beta-2
48~beta-3
48~beta-4
48~rc-1
48~rc-2
44.*
44.0-1
44.0-2
44.1-1
44.2-1
44.3-1
44.3-2
44.3-3
44.3-4
44.3-5
44.4-1
44.5-1
44.5-2
44.7-1
44.7-2
44.8-1
44.9-1
44.9-2
45.*
45.0-1
45.1-1
45.2-1
45.2-2
45.3-1
45.3-2
46.*
46.0-1
46.0-2
46.1-1
46.2-1
46.3.1-1
46.3.1-2
46.3.1-3
46.3.1-4
46.4-1
47.*
47.0-1
47.0-2
47.0-3
47.1-1
47.1-2
47.2-1
47.2-2
47.3-1
48.*
48.0-1
48.1-1
48.2-1
48.2-2
48.2-3
48.3-1
48.4-1~deb13u1
48.4-1
48.5-1
48.5-2
48.5-3
49.*
49.0-1
49.0-2
49.1-1
49.1-2
49.1-4
49.1-5
49.2-1
49.2-2
49.3-1
49.3-2
49.3-3
49.4-1
49.5-1
50.*
50.0-1
50.2-2
50.2-3
50.3-1
50.4-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-91786.json"

Debian:13 / gnome-shell

Package

Name
gnome-shell
Purl
pkg:deb/debian/gnome-shell?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

48.*
48.3-1
48.4-1~deb13u1
48.4-1
48.5-1
48.5-2
48.5-3
48.7-0+deb13u1
48.7-0+deb13u2
49.*
49.0-1
49.0-2
49.1-1
49.1-2
49.1-4
49.1-5
49.2-1
49.2-2
49.3-1
49.3-2
49.3-3
49.4-1
49.5-1
50.*
50.0-1
50.2-2
50.2-3
50.3-1
50.4-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-91786.json"

Debian:14 / gnome-shell

Package

Name
gnome-shell
Purl
pkg:deb/debian/gnome-shell?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

48.*
48.3-1
48.4-1~deb13u1
48.4-1
48.5-1
48.5-2
48.5-3
49.*
49.0-1
49.0-2
49.1-1
49.1-2
49.1-4
49.1-5
49.2-1
49.2-2
49.3-1
49.3-2
49.3-3
49.4-1
49.5-1
50.*
50.0-1
50.2-2
50.2-3
50.3-1
50.4-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-91786.json"