« List of all CVEs

CVE-2026-23868

Published: 3/10/2026 Last updated: 3/11/2026 Reserved: 1/16/2026

Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.

CNA assigner: Meta (4fc57720-52fe-4431-a0fb-3d2c8747b827) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 5.1 Medium CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Opam packages affected (1)

conf-libgif

Products affected (1)

Product Vendor Version
giflib giflib < 10.0.22621.4751

References (4)