CVE-2026-23868

EUVD-2026-10794
Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.1 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
Affected Products (NVD)
VendorProductVersion
giflib_projectgiflib
5.0.0 ≤
𝑥
≤ 6.1.1
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Enterprise Linux 10
0:5.2.1-22.el10_1.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10
0:5.2.1-24.el10_2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
0:5.2.1-22.el10_0.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support
0:4.1.6-9.el7_9.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
0:5.1.4-4.el8_10 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.2 Advanced Update Support
0:5.1.4-3.el8_2.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
0:5.1.4-3.el8_4.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
0:5.1.4-3.el8_4.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
0:5.1.4-3.el8_6.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Telecommunications Update Service
0:5.1.4-3.el8_6.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.6 Update Services for SAP Solutions
0:5.1.4-3.el8_6.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service
0:5.1.4-3.el8_8.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions
0:5.1.4-3.el8_8.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:5.2.1-10.el9_8.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:5.2.1-9.el9_7.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.0 Update Services for SAP Solutions
0:5.2.1-9.el9_0.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions
0:5.2.1-9.el9_2.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.4 Extended Update Support
0:5.2.1-9.el9_4.1 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
0:5.2.1-9.el9_6.1 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.2
1779223654 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.2
1779223651 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.2
1780681984 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.3
1778244559 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.3
1778244531 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.3
1778274666 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.3
1778244546 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
giflib
bookworm
5.2.1-2.5+deb12u1
fixed
bullseye
vulnerable
bullseye (security)
5.1.9-2+deb11u1
fixed
forky
6.1.3-1
fixed
sid
6.1.3-1
fixed
trixie
5.2.2-1+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
giflib
bionic
needed
focal
needed
jammy
needed
noble
needed
questing
ignored
resolute
needed
xenial
needed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
giflib-devel
suse enterprise desktop 15 SP7
5.2.2-150000.4.19.1
fixed
suse enterprise sap 15 SP7
5.2.2-150000.4.19.1
fixed
suse enterprise server 15 SP4
5.2.2-150000.4.19.1
fixed
suse enterprise server 15 SP7
5.2.2-150000.4.19.1
fixed
giflib-progs
suse enterprise server 12 SP3
5.0.6-13.12.1
fixed
libgif6
suse enterprise server 12 SP3
5.0.6-13.12.1
fixed
libgif6-32bit
suse enterprise server 12 SP3
5.0.6-13.12.1
fixed
libgif7
suse enterprise desktop 15 SP7
5.2.2-150000.4.19.1
fixed
suse enterprise sap 15 SP7
5.2.2-150000.4.19.1
fixed
suse enterprise server 15 SP4
5.2.2-150000.4.19.1
fixed
suse enterprise server 15 SP7
5.2.2-150000.4.19.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
giflib
RHEL 8
0:5.1.4-4.el8_10
fixed
RHEL 9
0:5.2.1-9.el9_7.1
fixed
giflib-devel
RHEL 8
0:5.1.4-4.el8_10
fixed
RHEL 9
0:5.2.1-9.el9_7.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
giflib
Amazon Linux 2
0:4.1.6-9.amzn2.0.5
fixed
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.3
fixed
giflib-debuginfo
Amazon Linux 2
0:4.1.6-9.amzn2.0.5
fixed
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.3
fixed
giflib-debugsource
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.3
fixed
giflib-devel
Amazon Linux 2
0:4.1.6-9.amzn2.0.5
fixed
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.3
fixed
giflib-utils
Amazon Linux 2
0:4.1.6-9.amzn2.0.5
fixed
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.3
fixed
giflib-utils-debuginfo
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.3
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
giflib
Azure Linux 3.0
0:5.2.1-11.azl3
fixed
CBL-Mariner 2.0
0:5.2.1-11.cm2
fixed