CyberRota Analysis
AI-GeneratedA vulnerability exists in gdk-pixbuf that affects applications processing specially crafted JPEG images with chunked ICC profile markers, leading to potential out-of-bounds writes due to stale metadata after buffer deallocation. This flaw can result in application crashes, making it critical for developers and organizations utilizing gdk-pixbuf version 2.26.4 or higher to prioritize patching and mitigating this risk. Users of image processing applications relying on gdk-pixbuf should also be vigilant against potential exploitation through malicious JPEG files.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image. Affected version >= 2.26.4