Updated gdk-pixbuf2.0 packages fix security vulnerabilities
Publication date: 18 Sep 2026Modification date: 18 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-7345 , CVE-2026-16768 , CVE-2026-81893
Description
Heap‑buffer‑overflow in gdk‑pixbuf. (CVE-2025-7345)
Out-of-bounds read in ico parser. (CVE-2026-16768)
Invalid write in jpeg icc profile parser on error recovery.
(CVE-2026-81893)
References
- https://bugs.mageia.org/show_bug.cgi?id=36238
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7DP4KY4CEXMYSH2LTCRQAN4JZKGOIKAV/
- https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/302
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MXN4IRXYCTUM4SHIHKYCZ4F65WY26VVT/
- https://lists.debian.org/debian-lts-announce/2025/10/msg00024.html
- https://www.cve.org/CVERecord?id=CVE-2025-7345
- https://www.cve.org/CVERecord?id=CVE-2026-16768
- https://www.cve.org/CVERecord?id=CVE-2026-81893
SRPMS
10/core
- gdk-pixbuf2.0-2.44.4-2.1.mga10
9/core
- gdk-pixbuf2.0-2.42.10-2.4.mga9