CVE-2026-23868

Publication date 10 March 2026

Last updated 6 August 2026


Ubuntu priority

Cvss 3 Severity Score

5.1 · Medium

Score breakdown

Description

Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.

Read the notes from the security team

Status

Package Ubuntu Release Status
giflib 26.04 LTS resolute
Fixed 5.2.2-1ubuntu3.2
25.10 questing Ignored end of life, was needed
24.04 LTS noble
Fixed 5.2.2-1ubuntu1.2
22.04 LTS jammy
Fixed 5.1.9-2ubuntu0.3
20.04 LTS focal
Vulnerable
18.04 LTS bionic
Vulnerable
16.04 LTS xenial
Vulnerable

Notes


mdeslaur

The commit listed below zeroes out sp->ExtensionBlockCount but then never updates it again, causing a regression.

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
giflib

Severity score breakdown

CVSS version: CVSS v3.0

Base score 5.1 · Medium

Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

References

Related Ubuntu Security Notices (USN)

Other references


Access our resources on patching vulnerabilities