Alerts This Week
Warning Icon 1 745
Alerts This Week
Warning Icon 1 745

Debian 11: libgd2 Important DoS Issues CVE-2021-38115 DLA-4411-1

debian lts
Calendar Grey December 16, 2025
Dist Debian Esm H88
Critical update for libgd2 addresses Denial of Service issues with multiple CVEs. Update recommended for users.
Vulnerabilities were found in libgd2, the GD Graphics Library, which could lead to Denial of Service via crafted input files

Summary

CVE-2021-38115

Maryam Ebrahimzadeh discovered an out-of-bounds read vulnerability
in read_header_tga(), which may lead to Denial of Service via a
crafted TGA file.

CVE-2021-40145

Maryam Ebrahimzadeh discovered a double free vulnerability in
gdImageGd2Ptr().

CVE-2021-40812

Maryam Ebrahimzadeh discovered out-of-bounds read vulnerabilities,
which may lead to Denial of Service via a crafted BMP or WebP file.

For Debian 11 bullseye, these problems have been fixed in version
2.3.0-2+deb11u1.

We recommend that you upgrade your libgd2 packages.

For the detailed security status of libgd2 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libgd2

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
important
Lowest
Low
Medium
High
Critical

Package: libgd2
Version: 2.3.0-2+deb11u1
CVE ID: CVE-2021-38115 CVE-2021-40145 CVE-2021-40812
Debian Bug: 991912

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here