Red Hat Product Errata RHSA-2026:11326 - Security Advisory Issued: 2026-04-28 Updated: 2026-04-28 RHSA-2026:11326 - Security Advisory Overview Updated Packages Synopsis Important: gdk-pixbuf2 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for gdk-pixbuf2 is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The gdk-pixbuf2 packages provide an image loading library that can be extended by loadable modules for new image formats. It is used by toolkits such as GTK+ or clutter. Security Fix(es): gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image (CVE-2026-5201) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.2 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x Fixes BZ - 2453291 - CVE-2026-5201 gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image CVEs CVE-2026-5201 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.2 SRPM gdk-pixbuf2-2.42.6-4.el9_2.1.src.rpm SHA-256: 4d45cdad03edf395b205495f3c06db230e7e6d01e2e2e04611e6baa48b33dbcf x86_64 gdk-pixbuf2-2.42.6-4.el9_2.1.i686.rpm SHA-256: abfcbc8870d26e3b7ca7c08a21f5dc5a489ce181f411d1f9cf44411839c35736 gdk-pixbuf2-2.42.6-4.el9_2.1.x86_64.rpm SHA-256: f13447d7004212dcd1d27231ba02d362c0d573009a976aa412f6d5419bc5fe6a gdk-pixbuf2-debuginfo-2.42.6-4.el9_2.1.i686.rpm SHA-256: a6f40c8dac6fd08738cd4e957d94fd869912ec04673691740b74a6a60bc12079 gdk-pixbuf2-debuginfo-2.42.6-4.el9_2.1.x86_64.rpm SHA-256: f5adf992241be70ca2cf2dda6f62460a479ea7fa7b3cf342f38396298d11606a gdk-pixbuf2-debugsource-2.42.6-4.el9_2.1.i686.rpm SHA-256: fc5f64cd74268a82584665d003faf0671d615744a5878b0c8ecbdac57e76bc81 gdk-pixbuf2-debugsource-2.42.6-4.el9_2.1.x86_64.rpm SHA-256: 8f77dd81ee0463d635e53b66bf1207b7c5527c0631b5b1251623ecfcaa763283 gdk-pixbuf2-devel-2.42.6-4.el9_2.1.i686.rpm SHA-256: 4328fd76439f285863e815015ce71b6da0f1f37dbdee9bca9f3053b45b8243a6 gdk-pixbuf2-devel-2.42.6-4.el9_2.1.x86_64.rpm SHA-256: a1932b0be93dada0f9a4fb60dd6cbccfb6a7d13d59e914e88243d33887c8aa18 gdk-pixbuf2-devel-debuginfo-2.42.6-4.el9_2.1.i686.rpm SHA-256: 37173839527fc3565725e8dfcfa45b41e45de3e3703161d6fcf7b5092f2bc34c gdk-pixbuf2-devel-debuginfo-2.42.6-4.el9_2.1.x86_64.rpm SHA-256: 6c069a88849ac39af8cc4fd4acdd1e6c37289a42299946e1ab08cd88eb0fc9e1 gdk-pixbuf2-modules-2.42.6-4.el9_2.1.i686.rpm SHA-256: 3444eff4eb5b29f734830f33b5154b0a0ea17af9eb336af428651b703e72939f gdk-pixbuf2-modules-2.42.6-4.el9_2.1.x86_64.rpm SHA-256: 5cc89adb09370859a8f41d61db30d3d42f9a45c82abce76c7406df0d1502a340 gdk-pixbuf2-modules-debuginfo-2.42.6-4.el9_2.1.i686.rpm SHA-256: b47d4d0df307b4d47c66b0858e55518ca1b65aee1e561385cd38e7090b3895f7 gdk-pixbuf2-modules-debuginfo-2.42.6-4.el9_2.1.x86_64.rpm SHA-256: 35911c04c7929f9b6dff78aa58a95e4eab853feee3901669c76602da2c534bc1 gdk-pixbuf2-tests-debuginfo-2.42.6-4.el9_2.1.i686.rpm SHA-256: 97e399f4dfe7a8bc70534f88ff71e75ffabb715c8c4ffeeebf3b5746f494113d gdk-pixbuf2-tests-debuginfo-2.42.6-4.el9_2.1.x86_64.rpm SHA-256: a673a2a1657003bc9d0b29490230c43dc6bb260f3b26a4d3e462e4a1b770be63 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 SRPM gdk-pixbuf2-2.42.6-4.el9_2.1.src.rpm SHA-256: 4d45cdad03edf395b205495f3c06db230e7e6d01e2e2e04611e6baa48b33dbcf ppc64le gdk-pixbuf2-2.42.6-4.el9_2.1.ppc64le.rpm SHA-256: 04a901e502fb8019504d25f29ae99425379dc026c1d13af01795569ab3904927 gdk-pixbuf2-debuginfo-2.42.6-4.el9_2.1.ppc64le.rpm SHA-256: 839ff7fb1b9b518e3c0eba3c610bbe57695777c906e7d1ad4d93ac4eac80dff8 gdk-pixbuf2-debugsource-2.42.6-4.el9_2.1.ppc64le.rpm SHA-256: 833b4cdf1c34c4b2e048fa2dbee9dabf7cab4980012b11071eea22690ae9526a gdk-pixbuf2-devel-2.42.6-4.el9_2.1.ppc64le.rpm SHA-256: 7da245f7bd7cdc1c99329c8315884b33776643462648a6f69d8556f557d6dd6a gdk-pixbuf2-devel-debuginfo-2.42.6-4.el9_2.1.ppc64le.rpm SHA-256: 74614daa664898f4b60539dcada01b6b3cad372d8a5cef3fc655786ab33e3e5e gdk-pixbuf2-modules-2.42.6-4.el9_2.1.ppc64le.rpm SHA-256: 0241ee2c6234d868b2c98c99433e8e39879688608a2f517051fcefea72494d0a gdk-pixbuf2-modules-debuginfo-2.42.6-4.el9_2.1.ppc64le.rpm SHA-256: 473ea69a648794307b413b00b284f7495f5055e54d0d6fd06cc3b9850968983f gdk-pixbuf2-tests-debuginfo-2.42.6-4.el9_2.1.ppc64le.rpm SHA-256: 5515f48f697bccdd7b4cacc83efbfe2688c73dce00e492e0d3987b4ead2a2290 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 SRPM gdk-pixbuf2-2.42.6-4.el9_2.1.src.rpm SHA-256: 4d45cdad03edf395b205495f3c06db230e7e6d01e2e2e04611e6baa48b33dbcf x86_64 gdk-pixbuf2-2.42.6-4.el9_2.1.i686.rpm SHA-256: abfcbc8870d26e3b7ca7c08a21f5dc5a489ce181f411d1f9cf44411839c35736 gdk-pixbuf2-2.42.6-4.el9_2.1.x86_64.rpm SHA-256: f13447d7004212dcd1d27231ba02d362c0d573009a976aa412f6d5419bc5fe6a gdk-pixbuf2-debuginfo-2.42.6-4.el9_2.1.i686.rpm SHA-256: a6f40c8dac6fd08738cd4e957d94fd869912ec04673691740b74a6a60bc12079 gdk-pixbuf2-debuginfo-2.42.6-4.el9_2.1.x86_64.rpm SHA-256: f5adf992241be70ca2cf2dda6f62460a479ea7fa7b3cf342f38396298d11606a gdk-pixbuf2-debugsource-2.42.6-4.el9_2.1.i686.rpm SHA-256: fc5f64cd74268a82584665d003faf0671d615744a5878b0c8ecbdac57e76bc81 gdk-pixbuf2-debugsource-2.42.6-4.el9_2.1.x86_64.rpm SHA-256: 8f77dd81ee0463d635e53b66bf1207b7c5527c0631b5b1251623ecfcaa763283 gdk-pixbuf2-devel-2.42.6-4.el9_2.1.i686.rpm SHA-256: 4328fd76439f285863e815015ce71b6da0f1f37dbdee9bca9f3053b45b8243a6 gdk-pixbuf2-devel-2.42.6-4.el9_2.1.x86_64.rpm SHA-256: a1932b0be93dada0f9a4fb60dd6cbccfb6a7d13d59e914e88243d33887c8aa18 gdk-pixbuf2-devel-debuginfo-2.42.6-4.el9_2.1.i686.rpm SHA-256: 37173839527fc3565725e8dfcfa45b41e45de3e3703161d6fcf7b5092f2bc34c gdk-pixbuf2-devel-debuginfo-2.42.6-4.el9_2.1.x86_64.rpm SHA-256: 6c069a88849ac39af8cc4fd4acdd1e6c37289a42299946e1ab08cd88eb0fc9e1 gdk-pixbuf2-modules-2.42.6-4.el9_2.1.i686.rpm SHA-256: 3444eff4eb5b29f734830f33b5154b0a0ea17af9eb336af428651b703e72939f gdk-pixbuf2-modules-2.42.6-4.el9_2.1.x86_64.rpm SHA-256: 5cc89adb09370859a8f41d61db30d3d42f9a45c82abce76c7406df0d1502a340 gdk-pixbuf2-modules-debuginfo-2.42.6-4.el9_2.1.i686.rpm SHA-256: b47d4d0df307b4d47c66b0858e55518ca1b65aee1e561385cd38e7090b3895f7 gdk-pixbuf2-modules-debuginfo-2.42.6-4.el9_2.1.x86_64.rpm SHA-256: 35911c04c7929f9b6dff78aa58a95e4eab853feee3901669c76602da2c534bc1 gdk-pixbuf2-tests-debuginfo-2.42.6-4.el9_2.1.i686.rpm SHA-256: 97e399f4dfe7a8bc70534f88ff71e75ffabb715c8c4ffeeebf3b5746f494113d gdk-pixbuf2-tests-debuginfo-2.42.6-4.el9_2.1.x86_64.rpm SHA-256: a673a2a1657003bc9d0b29490230c43dc6bb260f3b26a4d3e462e4a1b770be63 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 SRPM gdk-pixbuf2-2.42.6-4.el9_2.1.src.rpm SHA-256: 4d45cdad03edf395b205495f3c06db230e7e6d01e2e2e04611e6baa48b33dbcf aarch64 gdk-pixbuf2-2.42.6-4.el9_2.1.aarch64.rpm SHA-256: 465e14ad8e41c22e50ed0eb2875c32c9328d708022b5017f2f4e3577e16e71e9 gdk-pixbuf2-debuginfo-2.42.6-4.el9_2.1.aarch64.rpm SHA-256: b8c71dbda8761cb93463801f817052051c3ea9ccc7c9fe63be821341200728a4 gdk-pixbuf2-debugsource-2.42.6-4.el9_2.1.aarch64.rpm SHA-256: b734693a0a43741027bcd54001faec1b67fd56d3ca046a50a27438bbc3381dae gdk-pixbuf2-devel-2.42.6-4.el9_2.1.aarch64.rpm SHA-256: 27d1bf8ce8e3071b9c11fdb61eb3f14d7ec834548c58492ea8815ac852346fa4 gdk-pixbuf2-devel-debuginfo-2.42.6-4.el9_2.1.aarch64.rpm SHA-256: 93d14a4f9bae41c3c881ccf9e0d0d70a9e505cf58d0b87760f28b2f4c1782655 gdk-pixbuf2-modules-2.42.6-4.el9_2.1.aarch64.rpm SHA-256: 4184ec63427b036e17f397dbda4cdf5151cdd592fb4d13b50afd9b161a2a604c gdk-pixbuf2-modules-debuginfo-2.42.6-4.el9_2.1.aarch64.rpm SHA-256: 92643566d2ecfa9444d4b09caf9377a1029b53db89b8bbadb6d0b796515aea5f gdk-pixbuf2-tests-debuginfo-2.42.6-4.el9_2.1.aarch64.rpm SHA-256: ead6fa4fd1c4ba704157f4be5f7eab640cac7d686898a8ea75b2f26408f339b1 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 SRPM gdk-pixbuf2-2.42.6-4.el9_2.1.src.rpm SHA-256: 4d45cdad03edf395b205495f3c06db230e7e6d01e2e2e04611e6baa48b33dbcf s390x gdk-pixbuf2-2.42.6-4.el9_2.1.s390x.rpm SHA-256: 7f057a5214f6753e3aeeac53ad4147da78f543ad1c5d7920aab2926ce5b26f1b gdk-pixbuf2-debuginfo-2.42.6-4.el9_2.1.s390x.rpm SHA-256: aab4e804a06a8e5374925550f1eea616d3f7a7eb7813b85355a8a053182f12a4 gdk-pixbuf2-debugsource-2.42.6-4.el9_2.1.s390x.rpm SHA-256: f5e84306fc7f6488f55aef211a89e4353e655f8a6998823f0cb17c9a260d74ef gdk-pixbuf2-devel-2.42.6-4.el9_2.1.s390x.rpm SHA-256: 9330e7196268d592b8d0fcc746a8f90591bf87201592ae485c441cffaccc26ea gdk-pixbuf2-devel-debuginfo-2.42.6-4.el9_2.1.s390x.rpm SHA-256: 36189a7668521cf6ade08f58f9ea90c9b1d0fbb807b256588bcff00fe08a074
A heap-based buffer overflow vulnerability (CVE-2026-5201, CVSS 7.5 HIGH) in the gdk-pixbuf2 image loading library allows for a Denial of Service attack when a specially crafted JPEG image is processed. The flaw affects multiple Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions variants, and Red Hat has released updated packages to remediate the issue.