Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

Mageia giflib Critical Denial of Service Vuln 2026-0295 CVE-2026-26740

mageia
Calendar Grey July 25, 2026
Scroller Mageia
A critical security update for Mageia addresses a denial of service vulnerability in giflib affecting versions 10 and 9.
Mageia has released updates for versions 9 and 10 to fix a buffer overflow vulnerability in giflib v.5.2.2, which could lead to denial of service.

Summary

Description: The updated packages fix a security vulnerability: Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size. (CVE-2026-26740)

References

- https://bugs.mageia.org/show_bug.cgi?id=35614

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AG6LRGR6CTYC6R6KKFK2YTY2NJNGE62F/

- https://github.com/zakkanijia/POC/blob/main/giflib/giftool/giflib_giftool_gce_len_heap_oobwrite_disclosure.md

- https://sourceforge.net/p/giflib/bugs/199/

- https://www.cve.org/CVERecord?id=CVE-2026-26740

Resolution

SRPMS

- 10/core/giflib-5.2.2-4.1.mga10

- 9/core/giflib-5.2.1-7.4.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 25 Jul 2026 
URL: https://advisories.mageia.org/MGASA-2026-0295.html
Type: security
CVE: CVE-2026-26740

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.