CVE-2026-107651

NameCVE-2026-107651
DescriptionA flaw was found in Eye of GNOME (eog). A heap-based buffer overflow exists in the PNG metadata reader due to improper state handling when parsing split metadata chunks. A remote attacker could exploit this flaw by enticing a user into opening a specially crafted PNG file, potentially leading to arbitrary code execution or a Denial of Service (DoS) via application crash.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
eog (PTS)bookworm43.2-1vulnerable
trixie47.0-1vulnerable
forky, sid50.3-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
eogsource(unstable)(unfixed)

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2547986
https://gitlab.gnome.org/GNOME/eog/-/issues/342

Search for package or bug name: Reporting problems