CVE-2026-5201 is a heap-based buffer overflow in the gdk-pixbuf JPEG image loader caused by improper validation of color component counts when processing specially crafted JPEG images. Remote exploitation can occur without user interaction, including through automatic thumbnail generation, and can crash applications using the library. Arbitrary code execution is also identified as a possible consequence, although the conditions enabling that outcome are unspecified.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a standalone exploit research and proof-of-concept collection for CVE-2026-5201, a heap-based buffer overflow in GNOME gdk-pixbuf's JPEG loader on Linux. The core issue is a mismatch in the direct file-loading path: gdk-pixbuf allocates a pixel buffer based on expected RGB/RGBA channels, while libjpeg may emit 9 output components for a malformed arithmetic JPEG. The included Python reproducer (reproducer/craft_cve_2026_5201.py) generates a minimal malicious JPEG that declares 9 components in SOF10 but scans only 3 in SOS, producing a controlled overflow of roughly 49 KB for the default width. The repository also includes a patch showing the missing validation fix. Structure: README plus English/Turkish writeups document the vulnerability, impact, affected products, and fix. The patch directory contains the remediation patch. The reproducer directory contains the JPEG generator. The poc directory contains multiple C and Python programs: crash_test.c validates that gdk_pixbuf_new_from_file() is vulnerable while the incremental loader is safe; analyze_jpeg.py parses the crafted JPEG and computes overflow size; heap_analysis.c studies adjacent heap corruption; pixel_control_test.c uses libjpeg directly to inspect decompressed bytes and overflow-region values; find_dispose.c demonstrates that hijacking GObjectClass dispose() yields code execution; rce_shell.c simulates the overflow by redirecting g_class to a fake vtable and then verifies the real JPEG overflow primitive; aslr_bypass.c explores partial-pointer-overwrite concepts against ASLR; rce_32bit.c demonstrates a more complete 32-bit exploit path by mapping a fake vtable at 0x80808080 and executing /bin/sh shellcode. Capabilities: reliable denial of service via malformed JPEG parsing, heap corruption analysis, proof that adjacent GObject metadata can be overwritten, and local demonstrations of code-execution primitives under favorable conditions. This is not a remote network exploit by itself; the attack vector is delivery of a malicious JPEG file to any application using the vulnerable direct gdk-pixbuf loading API. Overall maturity is operational: the repository contains working crash/reproducer code and multiple exploit-development PoCs, but full universal weaponization is not shown for modern hardened 64-bit targets.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A heap-based buffer overflow in the gdk-pixbuf JPEG image loader allows a remote attacker to cause application crashes and denial of service through a specially crafted JPEG. Exploitation requires no user interaction and can occur during thumbnail generation. The listed CVSS v3 base score is 7.5 (High).
A remotely exploitable, low-complexity vulnerability requiring no privileges or user interaction, with impact limited to availability (CVSS v3 availability high; confidentiality and integrity none). The provided content does not identify the affected component or describe the underlying flaw.
A remotely exploitable, low-complexity vulnerability requiring no privileges or user interaction that affects availability of TencentOS Server 2, with no stated confidentiality or integrity impact.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.