CVE-2026-26740

EUVD-2026-12914
Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 23%
Affected Products (NVD)
VendorProductVersion
giflib_projectgiflib
5.2.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
giflib
bookworm
vulnerable
bullseye
vulnerable
forky
6.1.3-1
fixed
sid
6.1.3-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
giflib
bionic
deferred
focal
deferred
jammy
deferred
noble
deferred
questing
deferred
resolute
deferred
xenial
deferred
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
giflib
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.4
fixed
giflib-debuginfo
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.4
fixed
giflib-debugsource
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.4
fixed
giflib-devel
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.4
fixed
giflib-utils
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.4
fixed
giflib-utils-debuginfo
Amazon Linux 2023
0:5.2.1-9.amzn2023.0.4
fixed