#1149996 gegl: CVE-2026-103641

Package:
src:gegl
Source:
src:gegl
Submitter:
Salvatore Bonaccorso
Date:
2026-10-05 05:23:02 UTC
Severity:
normal
Tags:
#1149996#5
Date:
2026-10-05 05:22:11 UTC
From:
To:
Hi,

The following vulnerability was published for gegl.

CVE-2026-103641[0]:
| A flaw was found in GEGL. The Radiance HDR loader reads past the end
| of a memory-mapped image when an uncompressed scanline is shorter
| than the width declared in the file header. Opening a crafted HDR
| file crashes the application that uses the loader.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-103641
https://www.cve.org/CVERecord?id=CVE-2026-103641
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2544420
[2] https://gitlab.gnome.org/GNOME/gegl/-/commit/75214d1e6893d5a6b418a62ae6953a121c371a32

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore