Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Ubuntu has issued a security notice regarding vulnerabilities in GIFLIB affecting multiple LTS versions, potentially allowing remote attackers to crash the application or execute arbitrary code.. ========================================================================== Ubuntu Security Notice USN-8583-1 July 22, 2026 giflib vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: GIFLIB could be made to crash or run programs if it opened a specially crafted file. Software Description: - giflib: library for GIF images Details: It was discovered that GIFLIB incorrectly handled certain GIF image files. If a user or automated system were tricked into opening a specially crafted GIF file, a remote attacker could use this issue to cause GIFLIB to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS giflib-tools 5.2.2-1ubuntu3.2 libgif7 5.2.2-1ubuntu3.2 Ubuntu 24.04 LTS giflib-tools 5.2.2-1ubuntu1.2 libgif7 5.2.2-1ubuntu1.2 Ubuntu 22.04 LTS giflib-tools 5.1.9-2ubuntu0.3 libgif7 5.1.9-2ubuntu0.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8583-1 CVE-2026-23868, CVE-2026-26740 Package Information: https://launchpad.net/ubuntu/+source/giflib/5.2.2-1ubuntu3.2 https://launchpad.net/ubuntu/+source/giflib/5.2.2-1ubuntu1.2 https://launchpad.net/ubuntu/+source/giflib/5.1.9-2ubuntu0.3 . GIFLIB on Ubuntu could crash or run programs due to crafted GIF files, risking denial of service or code execution.. Ubuntu GIFLIB security update, denial of service GIFLIB,critical Ubuntu advisory. . Severity: Critical. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-19154 http://linux.oracle.com/errata/ELSA-2026-19154.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: giflib-5.2.1-25.el10_2.x86_64.rpm giflib-devel-5.2.1-25.el10_2.x86_64.rpm aarch64: giflib-5.2.1-25.el10_2.aarch64.rpm giflib-devel-5.2.1-25.el10_2.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/giflib-5.2.1-25.el10_2.src.rpm Related CVEs: CVE-2026-23868 Description of changes: [5.2.1-25] - fix CVE-2026-26740: buffer overflow in EGifGCBToExtension (RHEL-157086) [5.2.1-24] - rebuild [5.2.1-23] - fix CVE-2026-23868: double free in GifMakeSavedImage (RHEL-154850) _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-33502 http://linux.oracle.com/errata/ELSA-2026-33502.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: giflib-5.2.1-25.el10_2.x86_64.rpm giflib-devel-5.2.1-25.el10_2.x86_64.rpm aarch64: giflib-5.2.1-25.el10_2.aarch64.rpm giflib-devel-5.2.1-25.el10_2.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/giflib-5.2.1-25.el10_2.src.rpm Related CVEs: CVE-2026-26740 Description of changes: [5.2.1-25] - fix CVE-2026-26740: buffer overflow in EGifGCBToExtension (RHEL-157086) [5.2.1-24] - rebuild [5.2.1-23] - fix CVE-2026-23868: double free in GifMakeSavedImage (RHEL-154850) _______________________________________________ El-errata mailing list
Important: giflib security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:33502", "synopsis": "Important: giflib security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for giflib.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "giflib is a library for reading and writing gif images.\n\nSecurity Fix(es):\n\n* giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension (CVE-2026-26740)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2448747", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448747", "description": ""}], "cves": [{"name": "CVE-2026-26740", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26740", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-787"}], "references": [], "publishedAt": "2026-07-05T12:05:09.130757Z", "rpms": {"Rocky Linux 10": {"nvras": ["giflib-debugsource-0:5.2.1-25.el10_2.x86_64.rpm", "giflib-0:5.2.1-25.el10_2.aarch64.rpm", "giflib-devel-0:5.2.1-25.el10_2.x86_64.rpm", "giflib-0:5.2.1-25.el10_2.src.rpm", "giflib-0:5.2.1-25.el10_2.s390x.rpm", "giflib-devel-0:5.2.1-25.el10_2.ppc64le.rpm", "giflib-0:5.2.1-25.el10_2.x86_64.rpm", "giflib-devel-0:5.2.1-25.el10_2.aarch64.rpm", "giflib-debugsource-0:5.2.1-25.el10_2.ppc64le.rpm", "giflib-debugsource-0:5.2.1-25.el10_2.s390x.rpm", "giflib-debuginfo-0:5.2.1-25.el10_2.ppc64le.rpm", "giflib-debuginfo-0:5.2.1-25.el10_2.x86_64.rpm", "giflib-debuginfo-0:5.2.1-25.el10_2.s390x.rpm", "giflib-debugsource-0:5.2.1-25.el10_2.aarch64.rpm","giflib-0:5.2.1-25.el10_2.ppc64le.rpm", "giflib-debuginfo-0:5.2.1-25.el10_2.aarch64.rpm", "giflib-devel-0:5.2.1-25.el10_2.s390x.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important giflib security update for Rocky Linux addresses Denial of Service risk via buffer overflow in EGifGCBToExtension.. giflib security update, rocky linux security, buffer overflow fix, denial of service patch. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-33503 http://linux.oracle.com/errata/ELSA-2026-33503.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: giflib-5.1.4-5.el8_10.i686.rpm giflib-5.1.4-5.el8_10.x86_64.rpm giflib-devel-5.1.4-5.el8_10.i686.rpm giflib-devel-5.1.4-5.el8_10.x86_64.rpm aarch64: giflib-5.1.4-5.el8_10.aarch64.rpm giflib-devel-5.1.4-5.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/giflib-5.1.4-5.el8_10.src.rpm Related CVEs: CVE-2026-26740 Description of changes: [5.1.4-5] - fix CVE-2026-26740: buffer overflow in EGifGCBToExtension (RHEL-157097) _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-33501 http://linux.oracle.com/errata/ELSA-2026-33501.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: giflib-5.2.1-10.el9_8.2.i686.rpm giflib-5.2.1-10.el9_8.2.x86_64.rpm giflib-devel-5.2.1-10.el9_8.2.i686.rpm giflib-devel-5.2.1-10.el9_8.2.x86_64.rpm aarch64: giflib-5.2.1-10.el9_8.2.aarch64.rpm giflib-devel-5.2.1-10.el9_8.2.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/giflib-5.2.1-10.el9_8.2.src.rpm Related CVEs: CVE-2026-26740 Description of changes: [5.2.1-10.2] - fix CVE-2026-26740: buffer overflow in EGifGCBToExtension (RHEL-157133) _______________________________________________ El-errata mailing list
An update that solves one vulnerability can now be installed.. # Security update for giflib Announcement ID: SUSE-SU-2026:22382-1 Release Date: 2026-06-28T09:26:36Z Rating: important References: * bsc#1259836 Cross-References: * CVE-2026-26740 CVSS scores: * CVE-2026-26740 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-26740 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-26740 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-26740 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for giflib fixes the following issue * CVE-2026-26740: heap out-of-bounds read when processing a specially crafted GIF file containing a GCE block with a truncated extension byte count (bsc#1259836). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1098=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1098=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * giflib-devel-5.2.2-160000.4.1 * giflib-progs-5.2.2-160000.4.1 * giflib-progs-debuginfo-5.2.2-160000.4.1 * giflib-debugsource-5.2.2-160000.4.1 * libgif7-debuginfo-5.2.2-160000.4.1 * libgif7-5.2.2-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * giflib-devel-5.2.2-160000.4.1 * giflib-progs-5.2.2-160000.4.1 * giflib-debugsource-5.2.2-160000.4.1 * giflib-progs-debuginfo-5.2.2-160000.4.1 * libgif7-debuginfo-5.2.2-160000.4.1 * libgif7-5.2.2-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-26740.html * https://bugzilla.suse.com/show_bug.cgi?id=1259836 . An important SUSE update for giflib addresses CVE-2026-26740, fixing a heap overflow issue related to GIF processing.. SUSE Security Update,giflib CVE 2026-26740,giflib heap overflow. . Severity: Important. LinuxSecurity.com Team
Important: giflib security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:33501", "synopsis": "Important: giflib security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for giflib.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "giflib is a library for reading and writing gif images.\n\nSecurity Fix(es):\n\n* giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension (CVE-2026-26740)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2448747", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2448747", "description": ""}], "cves": [{"name": "CVE-2026-26740", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-26740", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-787"}], "references": [], "publishedAt": "2026-07-01T12:03:26.775911Z", "rpms": {"Rocky Linux 9": {"nvras": ["giflib-0:5.2.1-10.el9_8.2.aarch64.rpm", "giflib-0:5.2.1-10.el9_8.2.i686.rpm", "giflib-0:5.2.1-10.el9_8.2.ppc64le.rpm", "giflib-0:5.2.1-10.el9_8.2.s390x.rpm", "giflib-0:5.2.1-10.el9_8.2.src.rpm", "giflib-0:5.2.1-10.el9_8.2.x86_64.rpm", "giflib-debuginfo-0:5.2.1-10.el9_8.2.aarch64.rpm", "giflib-debuginfo-0:5.2.1-10.el9_8.2.i686.rpm", "giflib-debuginfo-0:5.2.1-10.el9_8.2.ppc64le.rpm", "giflib-debuginfo-0:5.2.1-10.el9_8.2.s390x.rpm", "giflib-debuginfo-0:5.2.1-10.el9_8.2.x86_64.rpm", "giflib-debugsource-0:5.2.1-10.el9_8.2.aarch64.rpm", "giflib-debugsource-0:5.2.1-10.el9_8.2.i686.rpm", "giflib-debugsource-0:5.2.1-10.el9_8.2.ppc64le.rpm","giflib-debugsource-0:5.2.1-10.el9_8.2.s390x.rpm", "giflib-debugsource-0:5.2.1-10.el9_8.2.x86_64.rpm", "giflib-devel-0:5.2.1-10.el9_8.2.aarch64.rpm", "giflib-devel-0:5.2.1-10.el9_8.2.i686.rpm", "giflib-devel-0:5.2.1-10.el9_8.2.ppc64le.rpm", "giflib-devel-0:5.2.1-10.el9_8.2.s390x.rpm", "giflib-devel-0:5.2.1-10.el9_8.2.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important update for giflib fixing denial of service via buffer overflow in Rocky Linux 9. Immediate action recommended.. giflib security update, Rocky Linux, denial of service, buffer overflow, important security advisory. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.