Red Hat Product Errata RHSA-2026:8861 - Security Advisory Issued: 2026-04-20 Updated: 2026-04-20 RHSA-2026:8861 - Security Advisory Overview Updated Packages Synopsis Important: giflib security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for giflib is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description giflib is a library for reading and writing gif images. Security Fix(es): giflib: Giflib: Double-free vulnerability leading to memory corruption (CVE-2026-23868) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for x86_64 8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le Red Hat CodeReady Linux Builder for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2446207 - CVE-2026-23868 giflib: Giflib: Double-free vulnerability leading to memory corruption CVEs CVE-2026-23868 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM giflib-5.1.4-4.el8_10.src.rpm SHA-256: 5d17ab177db89cb226a1821677ddda012d5ba6ddfaf95f59331baff47985a598 x86_64 giflib-5.1.4-4.el8_10.i686.rpm SHA-256: 649a0061ab234a2e5d268eca9a52ec44c62d9659c3b7e312c986e95ecbde0139 giflib-5.1.4-4.el8_10.x86_64.rpm SHA-256: d742c564fe95601fb580348b0a821b9cc3afc43e0126ca99e10e081acc42c8e8 giflib-debuginfo-5.1.4-4.el8_10.i686.rpm SHA-256: 4b83a5dbfa79a99613e7be8fc5171ef3f0d9ceadc145cb0d0c2e66e7dd67d339 giflib-debuginfo-5.1.4-4.el8_10.x86_64.rpm SHA-256: 9b383ea5e60d0f77df63224143d9d18bae0a895a5537402d86097b6fc366887e giflib-debugsource-5.1.4-4.el8_10.i686.rpm SHA-256: 2609a7de54e128c4511ac66d2d5663fdef2a4b1d553742679db347ac495c11c2 giflib-debugsource-5.1.4-4.el8_10.x86_64.rpm SHA-256: 1b072cb394234fad1075fa511f456be06ab77f82fa8fa078807ce40f3ef97ef1 giflib-utils-debuginfo-5.1.4-4.el8_10.i686.rpm SHA-256: 90eba1ba444eaf2d20ca67bd315cc6d3b2cf4ab6309ee322f6b0d5de1aa52aa5 giflib-utils-debuginfo-5.1.4-4.el8_10.x86_64.rpm SHA-256: a48340618318af1a0167a280735ee80156a910f04d035bf8f6c0b1f14dc38acf Red Hat Enterprise Linux for IBM z Systems 8 SRPM giflib-5.1.4-4.el8_10.src.rpm SHA-256: 5d17ab177db89cb226a1821677ddda012d5ba6ddfaf95f59331baff47985a598 s390x giflib-5.1.4-4.el8_10.s390x.rpm SHA-256: 7d2807003a97dc3d345df383cc247768ba8d6b554fd01cde9c9e735057f20868 giflib-debuginfo-5.1.4-4.el8_10.s390x.rpm SHA-256: 8d5825dde8d370257b395bfc64c02040bc67733a01ec66efc434f1cabd0d6e3d giflib-debugsource-5.1.4-4.el8_10.s390x.rpm SHA-256: 80bffef89a29b18cedd42f34cdf4cdb0aa71ec8e3ef6ec852f05df8976ab5bde giflib-utils-debuginfo-5.1.4-4.el8_10.s390x.rpm SHA-256: 9f75809c0db73b108520dbc375e8c001727e865ce3caa78a1d27584b2d2f5a24 Red Hat Enterprise Linux for Power, little endian 8 SRPM giflib-5.1.4-4.el8_10.src.rpm SHA-256: 5d17ab177db89cb226a1821677ddda012d5ba6ddfaf95f59331baff47985a598 ppc64le giflib-5.1.4-4.el8_10.ppc64le.rpm SHA-256: 80a3058ee8831c2927317f2f9cc4c4c51f853c5479674e590819c6da64d61451 giflib-debuginfo-5.1.4-4.el8_10.ppc64le.rpm SHA-256: f8c6ea013e363a17083d5307fc6acfba48267732bd11d3f511140ddab7329aa7 giflib-debugsource-5.1.4-4.el8_10.ppc64le.rpm SHA-256: 1d5c2a0874af323ddbd015786a35f22bd82c9240e148b07b41b1449277f2214f giflib-utils-debuginfo-5.1.4-4.el8_10.ppc64le.rpm SHA-256: 39e1e2e8f30c43bd6fd4219d6b10f3347043ca95f40d9a7c0de76609f34f7f78 Red Hat Enterprise Linux for ARM 64 8 SRPM giflib-5.1.4-4.el8_10.src.rpm SHA-256: 5d17ab177db89cb226a1821677ddda012d5ba6ddfaf95f59331baff47985a598 aarch64 giflib-5.1.4-4.el8_10.aarch64.rpm SHA-256: dc6aec16088feef381049ef49c7f3aa7d944de4a409bc8445a9dacbde5bcebcb giflib-debuginfo-5.1.4-4.el8_10.aarch64.rpm SHA-256: 2f03a2e3ce162618aa255631c9157858f4e0a9c7ca0b6dc82eca54e153261a60 giflib-debugsource-5.1.4-4.el8_10.aarch64.rpm SHA-256: 24776528c876f7b2207aacbbe12380fd20e635561de3c5951db869d1734c43fc giflib-utils-debuginfo-5.1.4-4.el8_10.aarch64.rpm SHA-256: 06053f112ea79e547b00ee690454299f0384aa95e71b4ce661bae68e94e7b870 Red Hat CodeReady Linux Builder for x86_64 8 SRPM x86_64 giflib-debuginfo-5.1.4-4.el8_10.i686.rpm SHA-256: 4b83a5dbfa79a99613e7be8fc5171ef3f0d9ceadc145cb0d0c2e66e7dd67d339 giflib-debuginfo-5.1.4-4.el8_10.x86_64.rpm SHA-256: 9b383ea5e60d0f77df63224143d9d18bae0a895a5537402d86097b6fc366887e giflib-debugsource-5.1.4-4.el8_10.i686.rpm SHA-256: 2609a7de54e128c4511ac66d2d5663fdef2a4b1d553742679db347ac495c11c2 giflib-debugsource-5.1.4-4.el8_10.x86_64.rpm SHA-256: 1b072cb394234fad1075fa511f456be06ab77f82fa8fa078807ce40f3ef97ef1 giflib-devel-5.1.4-4.el8_10.i686.rpm SHA-256: 38039b49bd98804b3fabac81b133df7dc01f65bcf9802c7de2a494ca7c0fbb5b giflib-devel-5.1.4-4.el8_10.x86_64.rpm SHA-256: 1b684df72d3b7b8002ce687d6b13965b3bb7ce16bc921373a75cdb97d7cd3cdc giflib-utils-debuginfo-5.1.4-4.el8_10.i686.rpm SHA-256: 90eba1ba444eaf2d20ca67bd315cc6d3b2cf4ab6309ee322f6b0d5de1aa52aa5 giflib-utils-debuginfo-5.1.4-4.el8_10.x86_64.rpm SHA-256: a48340618318af1a0167a280735ee80156a910f04d035bf8f6c0b1f14dc38acf Red Hat CodeReady Linux Builder for Power, little endian 8 SRPM ppc64le giflib-debuginfo-5.1.4-4.el8_10.ppc64le.rpm SHA-256: f8c6ea013e363a17083d5307fc6acfba48267732bd11d3f511140ddab7329aa7 giflib-debugsource-5.1.4-4.el8_10.ppc64le.rpm SHA-256: 1d5c2a0874af323ddbd015786a35f22bd82c9240e148b07b41b1449277f2214f giflib-devel-5.1.4-4.el8_10.ppc64le.rpm SHA-256: 67aac125bcb4e9e900ca49ae967e67c0607dbd79e229f9c29770f2498c6d86a6 giflib-utils-debuginfo-5.1.4-4.el8_10.ppc64le.rpm SHA-256: 39e1e2e8f30c43bd6fd4219d6b10f3347043ca95f40d9a7c0de76609f34f7f78 Red Hat CodeReady Linux Builder for ARM 64 8 SRPM aarch64 giflib-debuginfo-5.1.4-4.el8_10.aarch64.rpm SHA-256: 2f03a2e3ce162618aa255631c9157858f4e0a9c7ca0b6dc82eca54e153261a60 giflib-debugsource-5.1.4-4.el8_10.aarch64.rpm SHA-256: 24776528c876f7b2207aacbbe12380fd20e635561de3c5951db869d1734c43fc giflib-devel-5.1.4-4.el8_10.aarch64.rpm SHA-256: 17c411a8685e07dbf9a7fc70d94d7db1b741fd88f70ffb87fd76e1fc00783d14 giflib-utils-debuginfo-5.1.4-4.el8_10.aarch64.rpm SHA-256: 06053f112ea79e547b00ee690454299f0384aa95e71b4ce661bae68e94e7b870 Red Hat CodeReady Linux Builder for IBM z Systems 8 SRPM s390x giflib-debuginfo-5.1.4-4.el8_10.s390x.rpm SHA-256: 8d5825dde8d370257b395bfc64c02040bc67733a01ec66efc434f1cabd0d6e3d giflib-debugsource-5.1.4-4.el8_10.s390x.rpm SHA-256: 80bffef89a29b18cedd42f34cdf4cdb0aa71ec8e3ef6ec852f05df8976ab5bde giflib-devel-5.1.4-4.el8_10.s390x.rpm SHA-256: a7bce635e826c21aff44304b09d8a08e97892cc9ded86643b4f9d780c289b79a giflib-utils-debuginfo-5.1.4-4.el8_10.s390x.rpm SHA-256: 9f75809c0db73b108520dbc375e8c001727e865ce3caa78a1d27584b2d2f5a24 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 SRPM giflib-5.1.4-4.el8_10.src.rpm SHA-256: 5d17ab177db89cb226a1821677ddda012d5ba6ddfaf95f59331baff47985a598 x86_64 giflib-5.1.4-4.el8_10.i686.rpm SHA-256: 649a0061ab234a2e5d268eca9a52ec44c62d9659c3b7e312c986e95ecbde0139 giflib-5.1.4-4.el8_10.x86_64.rpm SHA-256: d742c564fe95601fb580348b0a821b9cc3afc43e0126ca99e10e081acc42c8e8 giflib-debuginfo-5.1.4-4.el8_10.i686.rpm SHA-256: 4b83a5dbfa79a99613e7be8fc5171ef3f0d9ceadc145cb0d0c2e66e7dd67d339 giflib-debuginfo-5.1.4-4.el8_10.x86_64.rpm SHA-256: 9b383ea5e60d0f77df63224143d9d18bae0a895a5537402d86097b6fc366887e giflib-debugsource-5.1.4-4.el8_10.i686.rpm SHA-256: 2609a7de54e128c4511ac66d2d5663fdef2a4b1d553742679db347ac495c11c2 giflib-debugsource-5.1.4-4.el8_10.x86_64.rpm SHA-256: 1b072cb394234fad1075fa511f456be06ab77f82fa8fa078807ce40f3ef97ef1 giflib-utils-debuginfo-5.1.4-4.el8_10.i686.rpm SHA-256: 90eba1ba444eaf2d20ca67bd315cc6d3b2cf4ab6309ee322f6b0d5de1aa52aa5 giflib-utils-debuginfo-5.1.4-4.el8_10.x86_64.rpm SHA-256: a48340618318af1a0167a280735ee80156a910f04d035bf8f6c0b1f14dc38acf Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 SRPM giflib-5.1.4-4.el8_10.src.rpm SHA-256: 5d17ab177db89cb226a1821677ddda012d5ba6ddfaf95f59331baff47985a598 aarch64 giflib-5.1.4-4.el8_10.aarch64.rpm SHA-256: dc6aec16088feef381049ef49c7f3aa7d944de4a409bc8445a9dacbde5bcebcb giflib-debuginfo-5.1.4-4.el8_10.aarch64.rpm SHA-256: 2f03a2e3ce162618aa255631c9157858f4e0a9c7ca0b6dc82eca54e153261a60 giflib-debugsource-5.1.4-4.el8_10.aarch64.rpm SHA-256: 24776528c876f7b2207aacbbe12380fd20e635561de3c5951db869d1734c43fc giflib-utils-debuginfo-5.1.4-4.el8_10.aarch64.rpm SHA-256: 06053f112ea79e547b00ee690454299f0384aa95e71b4ce661bae68e94e7b870 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 SRPM giflib-5.1.4-4.el8_10.src.rpm SHA-256: 5d17ab177db89cb226a1821677ddda012d5ba6ddfaf95f59331baff47985a598 ppc64le giflib-5.1.4-4.el8_10.ppc64le.rpm SHA-256: 80a3058ee8831c2927317f2f9cc4c4c51f853c5479674e590819c6da64d61451 giflib-debuginfo-5.1.4-4.el8_10.ppc64le.rpm SHA-256: f8c6ea013e363a17083d5307fc6acfba482677
A double-free vulnerability (CVE-2026-23868) in the giflib library can lead to memory corruption when processing GIF images, with a CVSS 3.1 score of 5.1 (Medium). The security update is rated Important for Red Hat Enterprise Linux 8 and its extended lifecycle variants. The advisory provides updated packages to remediate the issue, but specific affected and fixed version ranges for the library itself are not detailed in the provided text.