Logo
vulnerabilityCVE-2026-23868
Name
CVE-2026-23868
Source
NVD ( link)Debian ( link)
Description
Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
giflib
Exploitable

Vulnerability Ratings#


5.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
5.2.2
Patched
buildroot
master
6.1.3
Not Affected
openwrt
master
5.2.2-r2
Exploitable
yocto
kirkstone
5.2.2
Patched
yocto
master
6.1.2
Not Affected
yocto
scarthgap
5.2.2
Patched

Resolved with patches#


giflib (buildroot:2025.02.x)

#
Title
Author
Resolve
1
Patch #1
Thomas Perale <thomas.perale@mind.be>
CVE-2026-23868

giflib (yocto:kirkstone)

#
Title
Author
Resolve
1
Avoid potentuial double-free on weird images.
Eric S. Raymond <esr@thyrsus.com>
CVE-2026-23868

giflib (yocto:scarthgap)

#
Title
Author
Resolve
1
Avoid potentuial double-free on weird images.
Eric S. Raymond <esr@thyrsus.com>
CVE-2026-23868