#1148176 gnome-shell: CVE-2026-91786

Package:
src:gnome-shell
Source:
src:gnome-shell
Submitter:
Salvatore Bonaccorso
Date:
2026-09-17 21:23:03 UTC
Severity:
normal
Tags:
#1148176#5
Date:
2026-09-17 20:20:41 UTC
From:
To:
Hi,

The following vulnerability was published for gnome-shell.

CVE-2026-91786[0]:
| A flaw was found in GNOME Shell. When processing icons from a remote
| search provider via D-Bus, the system fails to validate the icon's
| declared dimensions against the actual data buffer size. A malicious
| or compromised remote search provider could exploit this by
| providing oversized icon dimensions, leading to an out-of-bounds
| read. This can cause the GNOME Shell process to crash, disrupting
| the user's session, and potentially disclose sensitive information
| from adjacent memory.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-91786
https://www.cve.org/CVERecord?id=CVE-2026-91786
[1] https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/9365
[2] https://gitlab.gnome.org/GNOME/gnome-shell/-/merge_requests/4417

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1148176#10
Date:
2026-09-17 21:21:28 UTC
From:
To:
Version: 50.5-1

This appears to have been fixed in 50.5 and 51.0 upstream.

According to discussion upstream, probably a more important attack route
is that if a sandboxed app is given direct access to
org.freedesktop.Notifications (as opposed to xdg-desktop-portal's
org.freedesktop.portal.Notification, which is designed to be used by
semi-trusted sandboxed apps, and validates the icon), it could present a
malformed icon data blob that way.

     smcv