Red Hat Product Errata RHSA-2026:11327 - Security Advisory Issued: 2026-04-28 Updated: 2026-04-28 RHSA-2026:11327 - Security Advisory Overview Updated Packages Synopsis Important: gdk-pixbuf2 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for gdk-pixbuf2 is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The gdk-pixbuf2 packages provide an image loading library that can be extended by loadable modules for new image formats. It is used by toolkits such as GTK+ or clutter. Security Fix(es): gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image (CVE-2026-5201) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2453291 - CVE-2026-5201 gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image CVEs CVE-2026-5201 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM gdk-pixbuf2-2.42.6-6.el9_6.1.src.rpm SHA-256: 93923e9e509be34b01501dbc898e47ed8e5984110b424d12387cac9928372574 x86_64 gdk-pixbuf2-2.42.6-6.el9_6.1.i686.rpm SHA-256: 6b57eb99606ce4213907e80fa28f545da3f715aa4aea73e9dfed166ac8348a85 gdk-pixbuf2-2.42.6-6.el9_6.1.x86_64.rpm SHA-256: c965e7077ba0a107345780bc58f21ee94a260fda5e0f57525e9fd0c04b1f08c5 gdk-pixbuf2-debuginfo-2.42.6-6.el9_6.1.i686.rpm SHA-256: d377ccd00c382ee974f31f3faa8e0ccbb688306e7d0d3e88776bac4969572118 gdk-pixbuf2-debuginfo-2.42.6-6.el9_6.1.x86_64.rpm SHA-256: c33b71e6a1e1331e4e174b4fddfef7269df335cef2188eeabb00154edd6067e3 gdk-pixbuf2-debugsource-2.42.6-6.el9_6.1.i686.rpm SHA-256: 495812385dd1c06100b97d5b7e8899794aca8a2a369e6566167fbb2ff5195870 gdk-pixbuf2-debugsource-2.42.6-6.el9_6.1.x86_64.rpm SHA-256: eca0551266f66db67d3224a10940c5012d3af28ea48cc1ff6ff201237e6bf66f gdk-pixbuf2-devel-2.42.6-6.el9_6.1.i686.rpm SHA-256: 02d0b0c6b66353f376b36549bc01bfbcb18f555f35c21b1172e9080204aded70 gdk-pixbuf2-devel-2.42.6-6.el9_6.1.x86_64.rpm SHA-256: cf603b33412e31c3e7bb46dda26ef3d4c7ea3b2cd5a0f68a41ff63e8bdab9bbc gdk-pixbuf2-devel-debuginfo-2.42.6-6.el9_6.1.i686.rpm SHA-256: cab656b6cfe5fc5f666f03fe9afb3b8060742217739e4edf9e6433cb3d9a2ed4 gdk-pixbuf2-devel-debuginfo-2.42.6-6.el9_6.1.x86_64.rpm SHA-256: 23a6ec1b4ec6cc4e6b6c0d12f2e0bbc19c3d881f6ac4c9a87b9e801e109eb76d gdk-pixbuf2-modules-2.42.6-6.el9_6.1.i686.rpm SHA-256: db1d1750115e14725b4a11a90458e544a29ac5f0c6f152c0d2934815288ab8f3 gdk-pixbuf2-modules-2.42.6-6.el9_6.1.x86_64.rpm SHA-256: 5dd6def5c8e4c57797a996f3f2964a7ea5743980e64e6d544a98a5b14c8c7b3a gdk-pixbuf2-modules-debuginfo-2.42.6-6.el9_6.1.i686.rpm SHA-256: 4e5ac9577009ed783b65c30c0301a23de6e42f2e5a677367ccf180ece4d623a3 gdk-pixbuf2-modules-debuginfo-2.42.6-6.el9_6.1.x86_64.rpm SHA-256: 81b7417e6cb02fa2da8a8b1962e63268a372566d00c7f3aaaf7a95114a101f96 gdk-pixbuf2-tests-debuginfo-2.42.6-6.el9_6.1.i686.rpm SHA-256: 2f87fbfd5589ebbb7d7fce9a7673b2fd5c01ba51841f85951f5347679c96b963 gdk-pixbuf2-tests-debuginfo-2.42.6-6.el9_6.1.x86_64.rpm SHA-256: fc8108c23038785b2f992f18097469883fdb0918d39d018aa35833887358268e Red Hat Enterprise Linux Server - AUS 9.6 SRPM gdk-pixbuf2-2.42.6-6.el9_6.1.src.rpm SHA-256: 93923e9e509be34b01501dbc898e47ed8e5984110b424d12387cac9928372574 x86_64 gdk-pixbuf2-2.42.6-6.el9_6.1.i686.rpm SHA-256: 6b57eb99606ce4213907e80fa28f545da3f715aa4aea73e9dfed166ac8348a85 gdk-pixbuf2-2.42.6-6.el9_6.1.x86_64.rpm SHA-256: c965e7077ba0a107345780bc58f21ee94a260fda5e0f57525e9fd0c04b1f08c5 gdk-pixbuf2-debuginfo-2.42.6-6.el9_6.1.i686.rpm SHA-256: d377ccd00c382ee974f31f3faa8e0ccbb688306e7d0d3e88776bac4969572118 gdk-pixbuf2-debuginfo-2.42.6-6.el9_6.1.x86_64.rpm SHA-256: c33b71e6a1e1331e4e174b4fddfef7269df335cef2188eeabb00154edd6067e3 gdk-pixbuf2-debugsource-2.42.6-6.el9_6.1.i686.rpm SHA-256: 495812385dd1c06100b97d5b7e8899794aca8a2a369e6566167fbb2ff5195870 gdk-pixbuf2-debugsource-2.42.6-6.el9_6.1.x86_64.rpm SHA-256: eca0551266f66db67d3224a10940c5012d3af28ea48cc1ff6ff201237e6bf66f gdk-pixbuf2-devel-2.42.6-6.el9_6.1.i686.rpm SHA-256: 02d0b0c6b66353f376b36549bc01bfbcb18f555f35c21b1172e9080204aded70 gdk-pixbuf2-devel-2.42.6-6.el9_6.1.x86_64.rpm SHA-256: cf603b33412e31c3e7bb46dda26ef3d4c7ea3b2cd5a0f68a41ff63e8bdab9bbc gdk-pixbuf2-devel-debuginfo-2.42.6-6.el9_6.1.i686.rpm SHA-256: cab656b6cfe5fc5f666f03fe9afb3b8060742217739e4edf9e6433cb3d9a2ed4 gdk-pixbuf2-devel-debuginfo-2.42.6-6.el9_6.1.x86_64.rpm SHA-256: 23a6ec1b4ec6cc4e6b6c0d12f2e0bbc19c3d881f6ac4c9a87b9e801e109eb76d gdk-pixbuf2-modules-2.42.6-6.el9_6.1.i686.rpm SHA-256: db1d1750115e14725b4a11a90458e544a29ac5f0c6f152c0d2934815288ab8f3 gdk-pixbuf2-modules-2.42.6-6.el9_6.1.x86_64.rpm SHA-256: 5dd6def5c8e4c57797a996f3f2964a7ea5743980e64e6d544a98a5b14c8c7b3a gdk-pixbuf2-modules-debuginfo-2.42.6-6.el9_6.1.i686.rpm SHA-256: 4e5ac9577009ed783b65c30c0301a23de6e42f2e5a677367ccf180ece4d623a3 gdk-pixbuf2-modules-debuginfo-2.42.6-6.el9_6.1.x86_64.rpm SHA-256: 81b7417e6cb02fa2da8a8b1962e63268a372566d00c7f3aaaf7a95114a101f96 gdk-pixbuf2-tests-debuginfo-2.42.6-6.el9_6.1.i686.rpm SHA-256: 2f87fbfd5589ebbb7d7fce9a7673b2fd5c01ba51841f85951f5347679c96b963 gdk-pixbuf2-tests-debuginfo-2.42.6-6.el9_6.1.x86_64.rpm SHA-256: fc8108c23038785b2f992f18097469883fdb0918d39d018aa35833887358268e Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 SRPM gdk-pixbuf2-2.42.6-6.el9_6.1.src.rpm SHA-256: 93923e9e509be34b01501dbc898e47ed8e5984110b424d12387cac9928372574 s390x gdk-pixbuf2-2.42.6-6.el9_6.1.s390x.rpm SHA-256: e9a31a6a46be5c144686f51607e5f8cfa6df87864ac8a9f94907aa8685fd3346 gdk-pixbuf2-debuginfo-2.42.6-6.el9_6.1.s390x.rpm SHA-256: 10673446166c71ad55f33d3d94934f29233fe019cde8208944dcbd38991bc032 gdk-pixbuf2-debugsource-2.42.6-6.el9_6.1.s390x.rpm SHA-256: 35c383da9d0e7a42b12d500d816aba115d6b6a41533f08b01b45b9dfbb3745d2 gdk-pixbuf2-devel-2.42.6-6.el9_6.1.s390x.rpm SHA-256: 18f0d4756053044ff1608baf10790d7ff00e4e4d4f6663095c5186368d8b1afc gdk-pixbuf2-devel-debuginfo-2.42.6-6.el9_6.1.s390x.rpm SHA-256: 5537daeea8db604a4e052750d14abb074c227f51b88f1e5e8622cd9ce9a59017 gdk-pixbuf2-modules-2.42.6-6.el9_6.1.s390x.rpm SHA-256: 49b2c1813eeb07d44b6f42353a09d72d33bbbc95ec834c11c89e5c6ccf668368 gdk-pixbuf2-modules-debuginfo-2.42.6-6.el9_6.1.s390x.rpm SHA-256: c09354d3520009bb4c2bcb1e8e5c100ea3aa53d04a9ef16d54509bc5fdef42b1 gdk-pixbuf2-tests-debuginfo-2.42.6-6.el9_6.1.s390x.rpm SHA-256: 1b83534fdf780de8b6c778f8184964b482acebae6d86f0477c58032e3bc23f34 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 SRPM gdk-pixbuf2-2.42.6-6.el9_6.1.src.rpm SHA-256: 93923e9e509be34b01501dbc898e47ed8e5984110b424d12387cac9928372574 ppc64le gdk-pixbuf2-2.42.6-6.el9_6.1.ppc64le.rpm SHA-256: 0e71af4762a03682767b1979bc36584c94b96ca9892231758fdf1fdc038bbddb gdk-pixbuf2-debuginfo-2.42.6-6.el9_6.1.ppc64le.rpm SHA-256: d930bbcb513d0a12305606087efec18cdfb27527fbbff7bcfd6718bd6d775c69 gdk-pixbuf2-debugsource-2.42.6-6.el9_6.1.ppc64le.rpm SHA-256: 7d913033eadee347da80e3da6500c109595e10781aca4f407e5dbef41d123730 gdk-pixbuf2-devel-2.42.6-6.el9_6.1.ppc64le.rpm SHA-256: d55af0f1657669a40c14412658d0a8e7fad86b441a8fef81651ea277e9f7b8d3 gdk-pixbuf2-devel-debuginfo-2.42.6-6.el9_6.1.ppc64le.rpm SHA-256: 9d6f970a95af7a318fc365d6fef196d219f847854437475865d7502282d750a3 gdk-pixbuf2-modules-2.42.6-6.el9_6.1.ppc64le.rpm SHA-256: be0a5ce09122073992d9f2424301c5b70803d895ab3a9647440496b95fe6e60f gdk-pixbuf2-modules-debuginfo-2.42.6-6.el9_6.1.ppc64le.rpm SHA-256: 2bf4f88a00480a9cb422322f495aa841791b081a1c4a012648e9a861f7316666 gdk-pixbuf2-tests-debuginfo-2.42.6-6.el9_6.1.ppc64le.rpm SHA-256: 961a9447216c534e9cd5e28b9c0521d250f3cca912c695ee1830ece509ad927c Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 SRPM gdk-pixbuf2-2.42.6-6.el9_6.1.src.rpm SHA-256: 93923e9e509be34b01501dbc898e47ed8e5984110b424d12387cac9928372574 aarch64 gdk-pixbuf2-2.42.6-6.el9_6.1.aarch64.rpm SHA-256: 28bbcf2f64c1d75f8cb333b882f4eb7fb67eb0c90e84d1d9eedeb99e41f96cff gdk-pixbuf2-debuginfo-2.42.6-6.el9_6.1.aarch64.rpm SHA-256: c5f4e0feb7860fbcccfa63721e8f37cf732ed18d6a1adfd4253cf5001719caed gdk-pixbuf2-debugsource-2.42.6-6.el9_6.1.aarch64.rpm SHA-256: 1ec18e48e90e2546da7899
A heap-based buffer overflow vulnerability (CVE-2026-5201, CVSS 7.5 HIGH) in the gdk-pixbuf2 image library allows for a Denial of Service attack when processing a specially crafted JPEG image. The flaw affects Red Hat Enterprise Linux 9.6 Extended Update Support and related variants. The security update is addressed in the gdk-pixbuf2-2.42.6-6.el9_6.1 package, which administrators should apply following Red Hat's standard patch procedures.