High severity7.8NVD Advisory· Published Jul 24, 2022· Updated Jun 17, 2026
CVE-2021-46829
CVE-2021-46829
Description
GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16- osv-coords11 versionspkg:rpm/almalinux/gdk-pixbuf2pkg:rpm/almalinux/gdk-pixbuf2-develpkg:rpm/almalinux/gdk-pixbuf2-modulespkg:rpm/opensuse/gdk-pixbuf&distro=openSUSE%20Tumbleweedpkg:rpm/suse/gdk-pixbuf&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/opensuse/gdk-pixbuf&distro=openSUSE%20Leap%2015.4pkg:rpm/suse/gdk-pixbuf&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/gdk-pixbuf&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP3pkg:rpm/suse/gdk-pixbuf&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/opensuse/gdk-pixbuf&distro=openSUSE%20Leap%20Micro%205.2pkg:rpm/opensuse/gdk-pixbuf&distro=openSUSE%20Leap%2015.3
< 2.42.6-3.el9+ 10 more
- (no CPE)range: < 2.42.6-3.el9
- (no CPE)range: < 2.42.6-3.el9
- (no CPE)range: < 2.42.6-3.el9
- (no CPE)range: < 2.42.8-2.1
- (no CPE)range: < 2.42.8-150400.5.3.1
- (no CPE)range: < 2.42.8-150400.5.3.1
- (no CPE)range: < 2.40.0-150200.3.6.1
- (no CPE)range: < 2.40.0-150200.3.6.1
- (no CPE)range: < 2.40.0-150200.3.6.1
- (no CPE)range: < 2.40.0-150200.3.6.1
- (no CPE)range: < 2.40.0-150200.3.6.1
<2.42.8+ 2 more
- (no CPE)range: <2.42.8
- (no CPE)
- cpe:2.3:a:gnome:gdk-pixbuf:*:*:*:*:*:*:*:*range: <2.42.8
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
9- gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/5398f04d772f7f8baf5265715696ed88db0f0512nvdPatchThird Party Advisory
- gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/bca00032ad68d0b0aa2c1f7558db931e52bd9cd2nvdPatchThird Party Advisory
- github.com/pedrib/PoC/blob/master/fuzzing/CVE-2021-46829/CVE-2021-46829.mdnvdExploitThird Party Advisory
- gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/190nvdExploitIssue TrackingThird Party Advisory
- gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/121nvdExploitThird Party Advisory
- www.openwall.com/lists/oss-security/2022/07/25/1nvdMailing ListThird Party Advisory
- www.debian.org/security/2022/dsa-5228nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2022/07/23/1nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5IHHEYFD6GDZVALKIPPRD2U4JNZUZWR/nvd
News mentions
0No linked articles in our index yet.