Changeflow GovPing Data Privacy & Cybersecurity gdk-pixbuf Vulnerability - Denial of Service an...
Priority review Notice Added Final

gdk-pixbuf Vulnerability - Denial of Service and Remote Code Execution Risk

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published March 31st, 2026
Detected April 1st, 2026
Email

Summary

CERT-Bund issued security advisory WID-SEC-2026-0945 warning of a high-severity vulnerability in gdk-pixbuf versions prior to 2.44.6. The vulnerability carries a CVSS Base Score of 7.5 (high) and enables remote attackers to perform denial of service attacks and potentially execute arbitrary code. Affected systems include UNIX operating systems running the GNOME image loading library.

What changed

CERT-Bund disclosed CVE-assigned vulnerability in gdk-pixbuf <2.44.6 affecting UNIX systems. The flaw allows remote, anonymous attackers to trigger denial of service conditions and potentially achieve arbitrary code execution through crafted image files. CVSS scores are 7.5 (Base) and 6.5 (Temporal), indicating high severity.

Organizations running gdk-pixbuf on UNIX systems must update to version 2.44.6 or later immediately. Security teams should apply available mitigations, monitor for vendor patches from Linux distributions, and audit systems for indicators of exploitation. This is an active vulnerability with remote attack capability requiring prompt patching.

What to do next

  1. Update gdk-pixbuf to version 2.44.6 or later on all affected UNIX systems
  2. Apply available mitigations referenced in the advisory
  3. Monitor for vendor-specific patches from Linux distributions and apply when available

Source document (simplified)

[WID-SEC-2026-0945] gdk-pixbuf: Schwachstelle ermöglicht Denial of Service und potenzielle Codeausführung CVSS Base Score 7.5 (hoch) CVSS Temporal Score 6.5 (mittel) Remoteangriff ja Datum 31.03.2026 Stand 01.04.2026 Mitigation ja

Betroffene Systeme

Betriebssystem

  • UNIX

Produktbeschreibung

GdkPixbuf ist eine GNOME-Bibliothek zum Laden und Verändern von Bildern.

Produkte

31.03.2026
- Open Source gdk-pixbuf <2.44.6

Angriff

Angriff

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in gdk-pixbuf ausnutzen, um einen Denial of Service Angriff durchzuführen und möglicherweise beliebigen Code auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Named provisions

Betroffene Systeme Angriff CVSS Base Score 7.5

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-Bund
Published
March 31st, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Minor
Document ID
WID-SEC-2026-0945

Who this affects

Applies to
Technology companies Manufacturers
Industry sector
5112 Software & Technology
Activity scope
Vulnerability Management Patch Management Security Incident Response
Threshold
gdk-pixbuf < 2.44.6
Geographic scope
Germany DE

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Topics
Software Security Open Source Vulnerabilities Denial of Service

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Optional. Personalizes your daily digest.

Free. Unsubscribe anytime.