Hi,
The following vulnerability was published for gnome-shell.
CVE-2026-91786[0]:
| A flaw was found in GNOME Shell. When processing icons from a remote
| search provider via D-Bus, the system fails to validate the icon's
| declared dimensions against the actual data buffer size. A malicious
| or compromised remote search provider could exploit this by
| providing oversized icon dimensions, leading to an out-of-bounds
| read. This can cause the GNOME Shell process to crash, disrupting
| the user's session, and potentially disclose sensitive information
| from adjacent memory.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-91786
https://www.cve.org/CVERecord?id=CVE-2026-91786
[1] https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/9365
[2] https://gitlab.gnome.org/GNOME/gnome-shell/-/merge_requests/4417
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore