CVE-2026-107651
Received Received - Intake

Heap-based Buffer Overflow in Eye of GNOME PNG Parser

Vulnerability report for CVE-2026-107651, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: redhat-SADP

Description

A flaw was found in Eye of GNOME (eog). A heap-based buffer overflow exists in the PNG metadata reader due to improper state handling when parsing split metadata chunks. A remote attacker could exploit this flaw by enticing a user into opening a specially crafted PNG file, potentially leading to arbitrary code execution or a Denial of Service (DoS) via application crash.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gnome eog *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap-based buffer overflow in Eye of GNOME (eog), specifically in the PNG metadata reader. It occurs due to improper state handling when parsing split metadata chunks in PNG files. An attacker can exploit this by tricking a user into opening a specially crafted PNG file, which may lead to arbitrary code execution or a Denial of Service (DoS) through application crash.

Detection Guidance

This vulnerability can be detected by checking the version of Eye of GNOME (eog) installed on your system. If your version is affected, update it immediately. Commands to check the version include 'eog --version' or 'dpkg -l eog' on Debian-based systems.

Impact Analysis

If you use Eye of GNOME to view PNG images, an attacker could exploit this flaw by providing a malicious PNG file. This could result in arbitrary code execution on your system, allowing the attacker to take control, or cause the application to crash, leading to a Denial of Service.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA. It is a local privilege escalation issue in Eye of GNOME that could lead to arbitrary code execution or DoS via a crafted PNG file. Compliance impact would depend on how the affected software is used in a system handling regulated data.

Mitigation Strategies

Immediately update Eye of GNOME to the latest patched version. Avoid opening untrusted PNG files until the update is applied. Monitor vendor advisories for further instructions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107651. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart