CyberRota
← Ana sayfaya dön

CVE-2026-16768

MEDIUM · CVSS 5.3

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-23T17:16:28.037 · Çekilme zamanı: 2026-07-24T00:25:03.530851+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-16768
Severity
MEDIUM
CVSS
5.3
EPSS
Yok

Orijinal NVD Açıklaması

A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail.