Red Hat Product Errata RHSA-2026:12062 - Security Advisory Issued: 2026-04-30 Updated: 2026-04-30 RHSA-2026:12062 - Security Advisory Overview Updated Packages Synopsis Important: gdk-pixbuf2 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for gdk-pixbuf2 is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The gdk-pixbuf2 packages provide an image loading library that can be extended by loadable modules for new image formats. It is used by toolkits such as GTK+ or clutter. Security Fix(es): gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image (CVE-2026-5201) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 Fixes BZ - 2453291 - CVE-2026-5201 gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image CVEs CVE-2026-5201 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 SRPM gdk-pixbuf2-2.36.12-7.el8_4.src.rpm SHA-256: 94181cf03ca8ebfa59ab0391c1ae5028679e99fbe213e8feb9525d9c3c949190 x86_64 gdk-pixbuf2-2.36.12-7.el8_4.i686.rpm SHA-256: 6743d01c553890c3a3b3ce2df24f5a484a0a7d2a1b7b42be75981ad71be6f8df gdk-pixbuf2-2.36.12-7.el8_4.x86_64.rpm SHA-256: 7a69934a7fe25a9884fc9141e9163c35f9fc40d73c1ad9fedb9ebb7f817c62cd gdk-pixbuf2-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: d8aacd7713c4fbd3ec8d53a19df4332d7996f5a6eb37397127360ed7742081ed gdk-pixbuf2-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: d8aacd7713c4fbd3ec8d53a19df4332d7996f5a6eb37397127360ed7742081ed gdk-pixbuf2-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 8d764b5615811063f643e04305cc479e280ac6baca984bb3a21cb0513a55bbef gdk-pixbuf2-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 8d764b5615811063f643e04305cc479e280ac6baca984bb3a21cb0513a55bbef gdk-pixbuf2-debugsource-2.36.12-7.el8_4.i686.rpm SHA-256: 6d4cb95added7480579e4fcb5b898eb12cf7474a2efa35ef300440d31dc0502d gdk-pixbuf2-debugsource-2.36.12-7.el8_4.i686.rpm SHA-256: 6d4cb95added7480579e4fcb5b898eb12cf7474a2efa35ef300440d31dc0502d gdk-pixbuf2-debugsource-2.36.12-7.el8_4.x86_64.rpm SHA-256: a463b8a84150e3ebaa831c9edec5585f7b26ba6529a4da13aafe73a179997b4e gdk-pixbuf2-debugsource-2.36.12-7.el8_4.x86_64.rpm SHA-256: a463b8a84150e3ebaa831c9edec5585f7b26ba6529a4da13aafe73a179997b4e gdk-pixbuf2-devel-2.36.12-7.el8_4.i686.rpm SHA-256: ff9bf50e57d52e180929da0bed5fd9babfbfc2d8a439a4d962f119994140df5d gdk-pixbuf2-devel-2.36.12-7.el8_4.x86_64.rpm SHA-256: 74ec7cc92f7d532735270c22034a0a2dae5a9f61650c984763a04ff99bb89611 gdk-pixbuf2-devel-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: d71839c2d4a29b8a5a44efed90b123fd92ebb1100016a74c136d5b6d85389f5e gdk-pixbuf2-devel-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: d71839c2d4a29b8a5a44efed90b123fd92ebb1100016a74c136d5b6d85389f5e gdk-pixbuf2-devel-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 61e07e1424664eead7c6af220a9ee2806b9091cf4490c1dd53db21fd0002d9dd gdk-pixbuf2-devel-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 61e07e1424664eead7c6af220a9ee2806b9091cf4490c1dd53db21fd0002d9dd gdk-pixbuf2-modules-2.36.12-7.el8_4.i686.rpm SHA-256: 0132c241676da2ef91d7c347a6c72d7524a3e582efddeaa7bd99bce3805b832e gdk-pixbuf2-modules-2.36.12-7.el8_4.x86_64.rpm SHA-256: 3742d997b70a91c5ee34d5a38bdbc76407573f66e49bf5c80ff4b3e3ef3af57e gdk-pixbuf2-modules-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: 59bf6b47953068a8d40b3d2f627d76e7f70755816028af2b1ffcd8a373f9f19f gdk-pixbuf2-modules-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: 59bf6b47953068a8d40b3d2f627d76e7f70755816028af2b1ffcd8a373f9f19f gdk-pixbuf2-modules-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 4e00815a7b7308cb53f57bd667b0d6c624efd5189c9bd68e8af51afe6b53b51d gdk-pixbuf2-modules-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 4e00815a7b7308cb53f57bd667b0d6c624efd5189c9bd68e8af51afe6b53b51d gdk-pixbuf2-tests-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: 3a33a24cbfedcb3e2e8e1f1687114914dd4efcdb6cef5bd6b968b7557694eeeb gdk-pixbuf2-tests-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: 3a33a24cbfedcb3e2e8e1f1687114914dd4efcdb6cef5bd6b968b7557694eeeb gdk-pixbuf2-tests-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 5a2b22448e3f49443bb36816f408ca9524183e194607a277f0120b14e7c97fcf gdk-pixbuf2-tests-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 5a2b22448e3f49443bb36816f408ca9524183e194607a277f0120b14e7c97fcf gdk-pixbuf2-xlib-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: b892705fb68c3ad50776f1872baa45c2e59ee47cf9312fd1e84a6f8068dedce6 gdk-pixbuf2-xlib-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: b892705fb68c3ad50776f1872baa45c2e59ee47cf9312fd1e84a6f8068dedce6 gdk-pixbuf2-xlib-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 3341c25715e43e4c674f43272b68c07c843fa389a047d2171dda6782158ac73d gdk-pixbuf2-xlib-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 3341c25715e43e4c674f43272b68c07c843fa389a047d2171dda6782158ac73d Red Hat Enterprise Linux Server - AUS 8.4 SRPM gdk-pixbuf2-2.36.12-7.el8_4.src.rpm SHA-256: 94181cf03ca8ebfa59ab0391c1ae5028679e99fbe213e8feb9525d9c3c949190 x86_64 gdk-pixbuf2-2.36.12-7.el8_4.i686.rpm SHA-256: 6743d01c553890c3a3b3ce2df24f5a484a0a7d2a1b7b42be75981ad71be6f8df gdk-pixbuf2-2.36.12-7.el8_4.x86_64.rpm SHA-256: 7a69934a7fe25a9884fc9141e9163c35f9fc40d73c1ad9fedb9ebb7f817c62cd gdk-pixbuf2-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: d8aacd7713c4fbd3ec8d53a19df4332d7996f5a6eb37397127360ed7742081ed gdk-pixbuf2-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: d8aacd7713c4fbd3ec8d53a19df4332d7996f5a6eb37397127360ed7742081ed gdk-pixbuf2-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 8d764b5615811063f643e04305cc479e280ac6baca984bb3a21cb0513a55bbef gdk-pixbuf2-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 8d764b5615811063f643e04305cc479e280ac6baca984bb3a21cb0513a55bbef gdk-pixbuf2-debugsource-2.36.12-7.el8_4.i686.rpm SHA-256: 6d4cb95added7480579e4fcb5b898eb12cf7474a2efa35ef300440d31dc0502d gdk-pixbuf2-debugsource-2.36.12-7.el8_4.i686.rpm SHA-256: 6d4cb95added7480579e4fcb5b898eb12cf7474a2efa35ef300440d31dc0502d gdk-pixbuf2-debugsource-2.36.12-7.el8_4.x86_64.rpm SHA-256: a463b8a84150e3ebaa831c9edec5585f7b26ba6529a4da13aafe73a179997b4e gdk-pixbuf2-debugsource-2.36.12-7.el8_4.x86_64.rpm SHA-256: a463b8a84150e3ebaa831c9edec5585f7b26ba6529a4da13aafe73a179997b4e gdk-pixbuf2-devel-2.36.12-7.el8_4.i686.rpm SHA-256: ff9bf50e57d52e180929da0bed5fd9babfbfc2d8a439a4d962f119994140df5d gdk-pixbuf2-devel-2.36.12-7.el8_4.x86_64.rpm SHA-256: 74ec7cc92f7d532735270c22034a0a2dae5a9f61650c984763a04ff99bb89611 gdk-pixbuf2-devel-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: d71839c2d4a29b8a5a44efed90b123fd92ebb1100016a74c136d5b6d85389f5e gdk-pixbuf2-devel-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: d71839c2d4a29b8a5a44efed90b123fd92ebb1100016a74c136d5b6d85389f5e gdk-pixbuf2-devel-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 61e07e1424664eead7c6af220a9ee2806b9091cf4490c1dd53db21fd0002d9dd gdk-pixbuf2-devel-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 61e07e1424664eead7c6af220a9ee2806b9091cf4490c1dd53db21fd0002d9dd gdk-pixbuf2-modules-2.36.12-7.el8_4.i686.rpm SHA-256: 0132c241676da2ef91d7c347a6c72d7524a3e582efddeaa7bd99bce3805b832e gdk-pixbuf2-modules-2.36.12-7.el8_4.x86_64.rpm SHA-256: 3742d997b70a91c5ee34d5a38bdbc76407573f66e49bf5c80ff4b3e3ef3af57e gdk-pixbuf2-modules-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: 59bf6b47953068a8d40b3d2f627d76e7f70755816028af2b1ffcd8a373f9f19f gdk-pixbuf2-modules-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: 59bf6b47953068a8d40b3d2f627d76e7f70755816028af2b1ffcd8a373f9f19f gdk-pixbuf2-modules-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 4e00815a7b7308cb53f57bd667b0d6c624efd5189c9bd68e8af51afe6b53b51d gdk-pixbuf2-modules-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 4e00815a7b7308cb53f57bd667b0d6c624efd5189c9bd68e8af51afe6b53b51d gdk-pixbuf2-tests-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: 3a33a24cbfedcb3e2e8e1f1687114914dd4efcdb6cef5bd6b968b7557694eeeb gdk-pixbuf2-tests-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: 3a33a24cbfedcb3e2e8e1f1687114914dd4efcdb6cef5bd6b968b7557694eeeb gdk-pixbuf2-tests-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 5a2b22448e3f49443bb36816f408ca9524183e194607a277f0120b14e7c97fcf gdk-pixbuf2-tests-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 5a2b22448e3f49443bb36816f408ca9524183e194607a277f0120b14e7c97fcf gdk-pixbuf2-xlib-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: b892705fb68c3ad50776f1872baa45c2e59ee47cf9312fd1e84a6f8068dedce6 gdk-pixbuf2-xlib-debuginfo-2.36.12-7.el8_4.i686.rpm SHA-256: b892705fb68c3ad50776f1872baa45c2e59ee47cf9312fd1e84a6f8068dedce6 gdk-pixbuf2-xlib-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 3341c25715e43e4c674f43272b68c07c843fa389a047d2171dda6782158ac73d gdk-pixbuf2-xlib-debuginfo-2.36.12-7.el8_4.x86_64.rpm SHA-256: 3341c25715e43e4c674f43272b68c07c843fa389a047d2171dda6782158ac73d The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
A heap-based buffer overflow vulnerability (CVE-2026-5201, CVSS 7.5 HIGH) in the gdk-pixbuf2 image library allows a denial-of-service attack when processing a specially crafted JPEG image. This update affects Red Hat Enterprise Linux 8.4 Advanced Mission Critical and Extended Update Support, with the fix provided in package version gdk-pixbuf2-2.36.12-7.el8_4.