CVE-2026-26740

EUVD-2026-12914
Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
Affected Products (NVD)
VendorProductVersion
giflib_projectgiflib
5.2.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
giflib
bookworm
vulnerable
bullseye
vulnerable
forky
vulnerable
sid
vulnerable
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
giflib
bionic
deferred
focal
deferred
jammy
deferred
noble
deferred
questing
deferred
resolute
deferred
xenial
deferred
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
java-25-openjdk
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-crypto-adapter
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-crypto-adapter-fastdebug
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-crypto-adapter-slowdebug
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-demo
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-demo-fastdebug
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-demo-slowdebug
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-devel
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-devel-fastdebug
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-devel-slowdebug
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-fastdebug
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-headless
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-headless-fastdebug
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-headless-slowdebug
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-javadoc
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-javadoc-zip
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-jmods
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-jmods-fastdebug
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-jmods-slowdebug
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-slowdebug
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-src
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-src-fastdebug
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-src-slowdebug
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-static-libs
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-static-libs-fastdebug
RHEL 9
1:25.0.3.0.9-1.el9
fixed
java-25-openjdk-static-libs-slowdebug
RHEL 9
1:25.0.3.0.9-1.el9
fixed