CVE-2026-23868

Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.
Configurations

Configuration 1 (hide)

cpe:2.3:a:giflib_project:giflib:*:*:*:*:*:*:*:*

History

07 May 2026, 18:18

Type Values Removed Values Added
CPE cpe:2.3:a:giflib_project:giflib:*:*:*:*:*:*:*:*
First Time Giflib Project
Giflib Project giflib
References () https://sourceforge.net/p/giflib/code/ci/f5b7267aed3665ef025c13823e454170d031c106/tree/gifalloc.c?diff=5146815377b7395944cb683a08c43eee3f631eb7 - () https://sourceforge.net/p/giflib/code/ci/f5b7267aed3665ef025c13823e454170d031c106/tree/gifalloc.c?diff=5146815377b7395944cb683a08c43eee3f631eb7 - Patch
References () https://www.facebook.com/security/advisories/cve-2026-23868 - () https://www.facebook.com/security/advisories/cve-2026-23868 - Third Party Advisory

11 Mar 2026, 16:16

Type Values Removed Values Added
CWE CWE-415
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.1

11 Mar 2026, 13:53

Type Values Removed Values Added
Summary
  • (es) Giflib contiene una vulnerabilidad de doble liberación que es el resultado de una copia superficial en GifMakeSavedImage y un manejo de errores incorrecto. Las condiciones necesarias para activar esta vulnerabilidad son difíciles pero pueden ser posibles.

10 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-10 20:16

Updated : 2026-05-07 18:18


NVD link : CVE-2026-23868

Mitre link : CVE-2026-23868

CVE.ORG link : CVE-2026-23868


JSON object : View

Products Affected

giflib_project

  • giflib
CWE
CWE-415

Double Free