rpm package
almalinux/giflib
pkg:rpm/almalinux/giflib
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-26740 | Hig | 8.2 | < 5.2.1-10.el9_8.2 | 5.2.1-10.el9_8.2 | Mar 18, 2026 | Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size. | |
| CVE-2026-23868 | Med | 5.1 | < 5.2.1-24.el10_2 | 5.2.1-24.el10_2 | Mar 10, 2026 | Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible. |
- affected < 5.2.1-10.el9_8.2fixed 5.2.1-10.el9_8.2
Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size.
- affected < 5.2.1-24.el10_2fixed 5.2.1-24.el10_2
Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.