Junglewise Threat Intelligence

CVE-2026-26740: giflib buffer overflow in EGifGCBToExtension

CVE-2026-26740 · Severity: high · CVSS 8.2 · Published 2026-03-18

Technologies: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9. Vendors: Red Hat.

Executive brief

A vulnerability has been identified in giflib, a widely used library for processing GIF images. An attacker can exploit this flaw by providing a specially crafted image file, which could cause applications using the library to crash or behave unexpectedly. This may lead to a disruption of services that rely on image processing, such as web servers or document viewers.

Technical details

A buffer overflow vulnerability exists in giflib version 5.2.2 within the EGifGCBToExtension and EGifGCBToSavedExtension functions in egif_lib.c. The issue stems from the library overwriting an existing Graphic Control Extension (GCE) block without properly validating the allocated size of the destination buffer. A remote, unauthenticated attacker can exploit this by providing a malformed GIF, leading to an out-of-bounds write. This can result in a denial of service (application crash) or potentially limited data corruption. While a fix was reported to be in the pipeline by upstream maintainers, it was not yet fully resolved at the time of the advisory.

Affected products

  • giflib project giflib 5.2.2
  • Red Hat Enterprise Linux 6
  • Red Hat Enterprise Linux 8
  • Red Hat Enterprise Linux 9
  • Red Hat Enterprise Linux 10

Timeline

  • 2026-03-18: disclosed: Initial disclosure of CVE-2026-26740
  • 2026-03-18: advisory: NVD publication date

References

Related threats