Medium severity6.1NVD Advisory· Published Sep 15, 2026· Updated Sep 15, 2026
CVE-2026-91786
CVE-2026-91786
Description
A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared dimensions against the actual data buffer size. A malicious or compromised remote search provider could exploit this by providing oversized icon dimensions, leading to an out-of-bounds read. This can cause the GNOME Shell process to crash, disrupting the user's session, and potentially disclose sensitive information from adjacent memory.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.