CVE-2026-91786
Received Received - Intake

GNOME Shell Out-of-Bounds Read via Remote Search Provider

Vulnerability report for CVE-2026-91786, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: redhat-SADP

Description

A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared dimensions against the actual data buffer size. A malicious or compromised remote search provider could exploit this by providing oversized icon dimensions, leading to an out-of-bounds read. This can cause the GNOME Shell process to crash, disrupting the user's session, and potentially disclose sensitive information from adjacent memory.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gnome gnome_shell *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds read flaw in GNOME Shell. When processing icons from remote search providers via D-Bus, the system fails to validate the icon's declared dimensions against the actual data buffer size. A malicious provider could exploit this by providing oversized dimensions, causing GNOME Shell to read beyond the buffer and crash the session.

Detection Guidance

This vulnerability involves GNOME Shell processing icons from remote search providers via D-Bus without validating icon dimensions against buffer size. Detection requires checking GNOME Shell versions and monitoring for crashes or memory leaks during icon rendering. No specific commands are provided in the context to directly detect this issue.

Impact Analysis

This vulnerability can cause GNOME Shell to crash, disrupting your session. It may also expose sensitive information from adjacent memory through the rendered icon, leading to potential data leaks. The impact includes low confidentiality loss, no integrity impact, and high availability impact.

Mitigation Strategies

Mitigation options are unavailable or do not meet ease of use criteria according to Red Hat. Users should monitor for updates from GNOME or their distribution vendors. Avoid using untrusted remote search providers until patches are available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91786. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart