A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
https://lists.debian.org/debian-lts-announce/2026/04/msg00010.html
https://bugzilla.redhat.com/show_bug.cgi?id=2453291
https://access.redhat.com/security/cve/CVE-2026-5201
https://access.redhat.com/errata/RHSA-2026:16174
https://access.redhat.com/errata/RHSA-2026:12115
https://access.redhat.com/errata/RHSA-2026:12114
https://access.redhat.com/errata/RHSA-2026:12062
https://access.redhat.com/errata/RHSA-2026:12061
https://access.redhat.com/errata/RHSA-2026:12060
https://access.redhat.com/errata/RHSA-2026:11806
https://access.redhat.com/errata/RHSA-2026:11328
https://access.redhat.com/errata/RHSA-2026:11327
https://access.redhat.com/errata/RHSA-2026:11326
https://access.redhat.com/errata/RHSA-2026:11325
https://access.redhat.com/errata/RHSA-2026:10741