CVE-2026-18090
Awaiting Analysis Awaiting Analysis - Queue

Heap Out-of-Bounds Read in Gdk-Pixbuf via Malicious ICNS File

Vulnerability report for CVE-2026-18090, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-14

Assigner: redhat-SADP

Description

A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gnome gdk-pixbuf *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a heap out-of-bounds read flaw in gdk-pixbuf. It occurs when processing specially crafted Apple Icon Image (.icns) files. The uncompress() function mishandles RLE-encoded ICNS data by not validating buffer boundaries during decompression. This can crash the application or leak sensitive memory data.

Impact Analysis

The impact includes application crashes leading to denial of service. It may also expose sensitive data from adjacent memory, potentially including user information or other confidential data processed by the application.

Mitigation Strategies

Update gdk-pixbuf to the latest patched version to address the heap out-of-bounds read issue in the uncompress() function handling ICNS files. Avoid opening untrusted Apple Icon Image files until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18090. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart