CVE-2026-103641
Received Received - Intake

GEGL Radiance HDR Loader Memory Corruption

Vulnerability report for CVE-2026-103641, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: redhat-SADP

Description

A flaw was found in GEGL. The Radiance HDR loader reads past the end of a memory-mapped image when an uncompressed scanline is shorter than the width declared in the file header. Opening a crafted HDR file crashes the application that uses the loader.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gegl gegl *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds memory read flaw in GEGL's Radiance HDR loader. When processing a crafted HDR file with an uncompressed scanline shorter than the declared width, the loader reads past the end of the memory-mapped image. This causes the application using the loader to crash upon opening the malicious file.

Detection Guidance

This vulnerability is triggered by opening a crafted HDR file in applications using GEGL. Detection involves monitoring for crashes when processing Radiance HDR files. Check application logs for segmentation faults after opening .hdr files. Use tools like strace or gdb to trace file operations and memory access patterns during file loading.

Impact Analysis

The primary impact is application crashes when opening untrusted Radiance HDR files. Since the flaw triggers a segmentation fault, it does not allow arbitrary code execution or unauthorized data access. The vulnerability requires local user interaction to exploit, meaning you must open a malicious file for it to affect you.

Compliance Impact

This vulnerability primarily causes application crashes due to out-of-bounds memory reads but does not directly lead to unauthorized data access or modification. For compliance with standards like GDPR or HIPAA, the impact is minimal since no data breaches or integrity violations occur. The main risk is service disruption from crashes, which may affect availability but not confidentiality or integrity of data.

Mitigation Strategies

Avoid opening untrusted Radiance HDR files in GEGL-dependent applications. Update GEGL to a patched version if available. Use alternative image viewers that do not rely on GEGL for HDR files. Implement file validation before processing to detect malformed headers or scanlines.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103641. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart