CVE-2026-5201Disclosure(gnome / enterprise_linux)

MEDIUMCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch gnome enterprise_linux systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component counts when processing a specially crafted JPEG image. A remote attacker can exploit this flaw without user interaction, for example, via thumbnail generation. Successful exploitation leads to application crashes and denial of service (DoS) conditions.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux
  • enterprise_linux_server_aus
  • enterprise_linux_server_tus
  • gdk-pixbuf

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 4d ago at 3 mentions (2026-03-31); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Products
enterprise_linuxenterprise_linux_server_ausenterprise_linux_server_tusgdk-pixbuf

8 versions affected across 4 products

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-03-31: 3Mentions · 2026-04-01: 1Mentions · 2026-04-09: 1Mentions · 2026-04-22: 1Mentions · 2026-05-01: 1PoC Mentioned / Linked · 2026-04-01: 1Exploit Tool / Code · 2026-04-01: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-05-01: 1Technical Details · 2026-03-31: 3Technical Details · 2026-04-01: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-22: 103-3104-0104-0904-2205-01
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
PoC
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-313
Disclosure3
2026-04-011
PoC1
2026-04-091
Patch1
2026-04-221
Disclosure1
2026-05-011
Patch1
Full discourse7 posts
  • Kağan@kagancapar
    PoC

    I discovered CVE-2026-5201. A heap buffer overflow in GNOME's gdk-pixbuf JPEG loader (CVSS 7.5). A 122-byte JPEG crashes any app using gdk_pixbuf_new_from_file(). RCE demonstrated on 32-bit via vtable hijack. Full write-up and PoCs: http://github.com/kagancapar/CVE-2026-5201 https://t.co/RWKokwuy1n

    Post summary

    The author reveals a heap buffer overflow (CVE-2026-5201) in GNOME’s gdk‑pixbuf JPEG loader, provides PoC code illustrating RCE via vtable hijack, but no patch, mitigation or wild exploitation is reported.

    116076396.0K
    2.3K followersView on X
  • Kağan@kagancapar
    Disclosure

    I discovered a high-severity (CVSS 7.5) Heap-based Buffer Overflow in GNOME's gdk-pixbuf, now assigned CVE-2026-5201. Thanks to GNOME & Red Hat for the rapid fix! It enables zero-click DoS & 32-bit ACE. Full technical write-up coming to GitHub soon. https://t.co/zjowDgpxgX

    Post summary

    The tweet announces the discovery of CVE‑2026‑5201, a high‑severity heap‑based buffer overflow in gdk‑pixbuf with zero‑click DoS potential, notes a rapid vendor fix, and promises a detailed write‑up on GitHub.

    2203952.5K
    2.3K followersView on X
  • Joel B.D.@darkshram
    Patch

    Disponibles nuevos paquetes de gdk-pixbuf2 para ALDOS, corrigiendo CVE-2026-5201 y CVE-2025-7345 vía @darkshram https://www.alcancelibre.org/noticias/disponibles-nuevos-paquetes-de-gdk-pixbuf2-para-aldos-corrigiendo-cve-2026-5201-y-cve-2025-7345

    Post summary

    New gdk-pixbuf2 packages for ALDOS have been released to fix CVE-2026-5201 and CVE-2025-7345, as announced by @darkshram.

    000001.0K
    1.0K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    CVE-2026-5201 (CVSS 8.2): A single malicious JPEG crashes your Linux app via gdk-pixbuf heap overflow. Read more: 👉 https://tinyurl.com/mv325yn4 #SUSE #OpenSUSE https://t.co/gMYFcEHOOr

    Post summary

    The tweet announces CVE-2026-5201, detailing a gdk-pixbuf heap overflow triggered by a malicious JPEG, and directs readers to a link for more information.

    0000073
    1.5K followersView on X
  • WindowsForum@windowsforum
    Patch

    🛑 Another day, another “just open a JPEG” DoS party. CVE-2026-5201 shows image parsers are still juicy targets—because Windows loves previewing untrusted files. https://windowsforum.com/threads/cve-2026-5201-gdk-pixbuf-jpeg-heap-overflow-patch-to-prevent-dos.411275/ #BufferOverflow #GdkPixbuf #Cve20265201 #JpegSecurity https://t.co/y6VIDk9igu

    Post summary

    The tweet discusses CVE‑2026‑5201, a JPEG heap overflow that can cause DoS, and points to a patch, with no evidence of active exploitation or PoC release.

    0000039
    1.1K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5201 - Gdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image Intel Report: https://ift.tt/it6LUOA

    Post summary

    A new CVE (CVE‑2026‑5201) for Gdk-pixbuf causing a heap‑based buffer overflow denial‑of‑service when processing crafted JPEG images has been reported; no PoC, exploit, active use, or patch information is provided.

    0000039
    281 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5201 A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation of color component … https://www.cve.org/CVERecord?id=CVE-2026-5201

    Post summary

    The post announces a heap‑based buffer overflow in gdk‑pixbuf’s JPEG loader, offering technical details but no PoC, exploit code, active exploitation evidence, patch, or false‑positive claim.

    0000078
    56.9K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appgnomegdk-pixbuf---
OSredhatenterprise_linux10.0--
OSredhatenterprise_linux7.0--
OSredhatenterprise_linux8.0--
OSredhatenterprise_linux9.0--
OSredhatenterprise_linux_server_aus8.2--
OSredhatenterprise_linux_server_aus8.4--
OSredhatenterprise_linux_server_tus8.8--

Explore more