CVE-2026-23868

EUVD-2026-10794
Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.1 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
Affected Products (NVD)
VendorProductVersion
giflib_projectgiflib
5.0.0 ≤
𝑥
≤ 6.1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
giflib
bookworm
vulnerable
bullseye
vulnerable
forky
6.1.3-1
fixed
sid
6.1.3-1
fixed
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
giflib
bionic
needed
focal
needed
jammy
needed
noble
needed
questing
needed
resolute
needed
xenial
needed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
giflib-devel
suse enterprise desktop 15 SP7
5.2.2-150000.4.19.1
fixed
suse enterprise sap 15 SP7
5.2.2-150000.4.19.1
fixed
suse enterprise server 15 SP4
5.2.2-150000.4.19.1
fixed
suse enterprise server 15 SP7
5.2.2-150000.4.19.1
fixed
giflib-progs
suse enterprise server 12 SP3
5.0.6-13.12.1
fixed
libgif6
suse enterprise server 12 SP3
5.0.6-13.12.1
fixed
libgif6-32bit
suse enterprise server 12 SP3
5.0.6-13.12.1
fixed
libgif7
suse enterprise desktop 15 SP7
5.2.2-150000.4.19.1
fixed
suse enterprise sap 15 SP7
5.2.2-150000.4.19.1
fixed
suse enterprise server 15 SP4
5.2.2-150000.4.19.1
fixed
suse enterprise server 15 SP7
5.2.2-150000.4.19.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
giflib
RHEL 8
0:5.1.4-4.el8_10
fixed
RHEL 9
0:5.2.1-9.el9_7.1
fixed
giflib-devel
RHEL 8
0:5.1.4-4.el8_10
fixed
RHEL 9
0:5.2.1-9.el9_7.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
giflib
Amazon Linux 2
0:4.1.6-9.amzn2.0.5
fixed
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.3
fixed
giflib-debuginfo
Amazon Linux 2
0:4.1.6-9.amzn2.0.5
fixed
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.3
fixed
giflib-debugsource
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.3
fixed
giflib-devel
Amazon Linux 2
0:4.1.6-9.amzn2.0.5
fixed
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.3
fixed
giflib-utils
Amazon Linux 2
0:4.1.6-9.amzn2.0.5
fixed
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.3
fixed
giflib-utils-debuginfo
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.3
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
giflib
Azure Linux 3.0
0:5.2.1-11.azl3
fixed
CBL-Mariner 2.0
0:5.2.1-11.cm2
fixed