#1145988 gdk-pixbuf: CVE-2026-81893

Package:
src:gdk-pixbuf
Source:
src:gdk-pixbuf
Submitter:
Salvatore Bonaccorso
Date:
2026-09-17 00:37:02 UTC
Severity:
normal
Tags:
#1145988#5
Date:
2026-08-28 14:32:37 UTC
From:
To:
Hi,

The following vulnerability was published for gdk-ppixbuf.

CVE-2026-81893[0]:
| A flaw was found in gdk-pixbuf. When loading a specially crafted
| JPEG image containing chunked ICC profile markers, an error during
| ICC profile parsing can leave stale size metadata after the profile
| buffer is freed. A subsequent allocation in the same decode can
| cause an out-of-bounds write, potentially crashing the application.
| To exploit this flaw, an application using gdk-pixbuf must process
| the malicious JPEG image.  Affected version >= 2.26.4


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-81893
https://www.cve.org/CVERecord?id=CVE-2026-81893
[1] https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/278
[2] https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/efe658674bd103d1c9bf50809d5767a3f6dd5a01

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1145988#12
Date:
2026-09-13 12:59:25 UTC
From:
To:
Control: retitle -1 gdk-pixbuf: CVE-2026-81893: OOB write when parsing crafted JPEG image's ICC profile
gdk-pixbuf >= 2.44.5+dfsg-3 loads most image formats using glycin rather than
its own C code. (Exceptions: .xpm, .xbm still use C code because the
equivalent Rust code in glycin was not feature-complete until recently.)

#1145988#19
Date:
2026-09-14 07:58:12 UTC
From:
To:
Hi Simon,

Thanks for the update. So at least at source-level it would still be
affected, will keep the tracking as it is for now (unless someone
objects). We have for now no clean way to state it becomes a
'nonissue' with only one suite. I have added though a note to clarify
the status.

Regards,
Salvatore

#1145988#22
Date:
2026-09-17 00:05:42 UTC
From:
To:
Hello,

Bug #1145988 in gdk-pixbuf reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/gnome-team/gdk-pixbuf/-/commit/4ab277d11b9d59001c84bbd6b35ae28b68f8b9aa
------------------------------------------------------------------------
d/patches: Address CVE-2026-81893

Release architectures were probably already not vulnerable to this,
because we use glycin to load JPEG images on release architectures.
The older JPEG loader written in C is still used on all -ports
architectures.

Closes: #1145988
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1145988

#1145988#29
Date:
2026-09-17 00:34:25 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
gdk-pixbuf, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1145988@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon McVittie <smcv@debian.org> (supplier of updated gdk-pixbuf package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 17 Sep 2026 01:04:45 +0100
Source: gdk-pixbuf
Architecture: source
Version: 2.44.8+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv@debian.org>
Closes: 1145988
Changes:
 gdk-pixbuf (2.44.8+dfsg-1) unstable; urgency=medium
 .
   * Team upload
   * New upstream release
   * d/control: Bump glycin dependency to 2.2~alpha.7 as per meson.build
   * d/p/jpeg-When-freeing-memory-unset-the-size.patch:
     Address CVE-2026-81893.
     Release architectures were probably already not vulnerable to this,
     because we use glycin to load JPEG images on release architectures.
     The older JPEG loader written in C is still used on all -ports
     architectures. (Closes: #1145988)
Checksums-Sha1:
 6d88a73c8a2859b71c3f9663339da1f6df58bf7f 3581 gdk-pixbuf_2.44.8+dfsg-1.dsc
 0f7824f51f5e059e1a63acc72362a8dfa4ecb705 5957984 gdk-pixbuf_2.44.8+dfsg.orig.tar.xz
 eae14f8e70b17b7010285850ca10a0e1f272f69c 26464 gdk-pixbuf_2.44.8+dfsg-1.debian.tar.xz
 7d3b05ae225abb0707bc515e019f1bec2297e9f4 7341176 gdk-pixbuf_2.44.8+dfsg-1.git.tar.xz
 ee6006e5beb5c23f5cd443dce849b6eb93989fb9 17704 gdk-pixbuf_2.44.8+dfsg-1_source.buildinfo
Checksums-Sha256:
 1c6b742f8aaa9fd761297a0370fdd9ba7f383f976814208cac38fa1f82600560 3581 gdk-pixbuf_2.44.8+dfsg-1.dsc
 d8353493a93fb9eddc66946e17e60a38c2e998f26f3822d11078938b9e962bc5 5957984 gdk-pixbuf_2.44.8+dfsg.orig.tar.xz
 812c0592d7b5f5d0f5f08e629489b2588e16a9297fb7a60c158d5d083f6b6fa3 26464 gdk-pixbuf_2.44.8+dfsg-1.debian.tar.xz
 b0161a30bf490671dad418bc0a848675aef88d2035828b044ed6acf3f7b7fc5a 7341176 gdk-pixbuf_2.44.8+dfsg-1.git.tar.xz
 76d55d767f9afce902a6196dc6845b5e1099013557361562d021516cf23a6249 17704 gdk-pixbuf_2.44.8+dfsg-1_source.buildinfo
Files:
 f1850f8da75cdeeee32ad03ccd2bb9d0 3581 libs optional gdk-pixbuf_2.44.8+dfsg-1.dsc
 35092f095e86b3c1623695a348d6925c 5957984 libs optional gdk-pixbuf_2.44.8+dfsg.orig.tar.xz
 2c428e0440c4180d8709e9829ee87fc7 26464 libs optional gdk-pixbuf_2.44.8+dfsg-1.debian.tar.xz
 8b4ae7e215ee2c2573d42b2788dca966 7341176 libs None gdk-pixbuf_2.44.8+dfsg-1.git.tar.xz
 692f694c4cd30be8fe24411aba41f4fd 17704 libs optional gdk-pixbuf_2.44.8+dfsg-1_source.buildinfo
Git-Tag-Info: tag=5536822ffbdd19fc91d967d7631c7d5378dc2564 fp=7a073ad1ae694fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie <smcv@debian.org>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqrLyoACgkQYG0ITkaD
wHkSLRAAnFmoQnpMd2JC5tu0VqgR/OVWG/vWZ4YrCskT4wtUX96AcCYbTNB3T7LH
+Xb5fvAPPPV4qACn7f2SA6vLU+iYPtGVqGWeO/t3uaugXb+i/mfHHiubh4O27lZV
sukntewDJu18hbSc/o5YE93HoL9NMexCh2JomD0FURfa+R9ei6U17vlK887bUOJn
ID6czjdvfJqza02ZHNGJ3tnuGG7PJk+vyed90ajEoWRbb8HRFpOyR9pm/1j3EMy/
Fj7AtTCKrl+bCFvA4R9752m9SPX5ruAlI2/u6u0QEvZvVBxDQD4ty5Eug++mMcpg
21yYcFB8NnuejDi6A9oQsVusb0XCoqPhDhplzdftxw6+vE9IAiRSPZK6uLamdx6F
qJRP8fZIG3Ka3/+ITwTqjNfZtKTYz1PCF1N/3naqvTtszvVm5///jMp4UI2q93s8
fFI6eKVrem7I3ArCiPOLUQs1qth+AbaxfzXSErmJbnPvlMgapy4k6XknvL4kcnrW
OARXDijWoUCfbRrElEOmIH8LgkKeLCnEQDwplN2lRj8zh1jV/qK9XYz+dWw1/Jup
T83T6Tt3rhCeVPw7tN5w5KZxyROCPOlnG6DiM6fIRa7J+t/+WTiar7KGekSMG4rr
1ybA7nXRr1lykfT4IuTN3aS/1lTZQb6/wh1IbpoZ1abnrHd+GfQ=
=Zt3A
-----END PGP SIGNATURE-----