CVE-2026-23868

Published: March 13, 2026Last modified: March 17, 2026

Description

Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.

Severity score breakdown

ParameterValue
Base score5.1
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgiflibFixed (5.2.2-r3)
25 LTSgiflibFixed (5.2.2-r2)
StreamgiflibFixed (5.2.2-r2)

References

ON THIS PAGE