A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.
https://lists.debian.org/debian-lts-announce/2026/04/msg00010.html
https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/304