This update for giflib fixes the following issue
- CVE-2026-26740: heap out-of-bounds read when processing a specially crafted GIF file containing a GCE block with a
truncated extension byte count (bsc#1259836).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-1098=1
- openSUSE Leap 16.0:
giflib-devel-5.2.2-160000.4.1
giflib-progs-5.2.2-160000.4.1
libgif7-5.2.2-160000.4.1
* bsc#1259836
References:
* https://www.suse.com/security/cve/CVE-2026-26740.html
Get the latest Linux and open source security news straight to your inbox.