Skip to content
Threat Feed

Vendor

GNOME

12 briefs RSS
high advisory

Use-After-Free Vulnerability in librsvg

A use-after-free vulnerability in librsvg (CVE-2026-96889) allows remote attackers to trigger memory corruption and potential code execution by providing specially crafted SVG documents.

librsvg
1c
medium advisory

Denial of Service Vulnerability in libxml2

A vulnerability in the libxml2 library allows a remote, unauthenticated attacker to trigger a denial of service condition through the submission of malformed XML data.

libxml2 denial-of-service vulnerability
1t 1c
high advisory

Local Privilege Escalation in gvfsd-admin via TOCTOU Race Condition

A Time-of-Check Time-of-Use (TOCTOU) race condition in the gvfsd-admin daemon allows local attackers to perform privilege escalation by manipulating symbolic links to modify ownership of arbitrary system files.

gvfs privilege-escalation linux gnome
1t 1c
medium advisory

Multiple Vulnerabilities in libxml2 Library

Multiple vulnerabilities within the libxml2 library could allow remote attackers to bypass security restrictions, manipulate data, disclose sensitive information, or trigger a denial-of-service condition.

libxml2 vulnerability gnome
1t
high advisory

Heap Use-After-Free in libsoup HTTP/2 Implementation

A heap use-after-free vulnerability in the libsoup HTTP/2 client allows malicious servers or MITM attackers to trigger memory corruption via specifically timed GOAWAY frames during file uploads.

libsoup vulnerability memory-corruption
1t 1c
high threat

Heap-Based Buffer Overflow in gvfs SFTP Backend

The gvfsd-sftp process contains a heap-based buffer overflow vulnerability that allows a malicious SFTP server to corrupt memory via crafted file read responses.

exploited gvfs vulnerability memory-corruption linux
1c
medium advisory

Potential Privilege Escalation via SUID/SGID Proxy Execution on Linux

Attackers may exploit SUID/SGID binaries like pkexec, su, or sudo on Linux systems to execute commands with elevated privileges, by identifying instances where a process runs with root privileges (user ID 0 or group ID 0) while the real user or group ID is non-root, allowing a low-privilege foothold to gain full system control.

su +17 privilege-escalation linux-security defense-evasion persistence system-exploitation
1r 4t
high threat

Libsoup HTTP/2 Frame Window Exhaustion Remote Denial of Service

A remote denial of service vulnerability, CVE-2026-15713, exists in the soupcache component of the Libsoup library due to a memory leak that leads to HTTP/2 frame window exhaustion, potentially causing application crashes or unresponsiveness.

exploited Libsoup denial-of-service vulnerability http/2 memory-leak
1c
high advisory

CVE-2026-58384: GIMP PSD Parser Integer Overflow Leads to RCE/DoS

An integer overflow vulnerability (CVE-2026-58384) exists in GIMP's PSD parser within the `read_RLE_channel()` function, leading to undersized heap allocations that can cause subsequent heap memory corruption, potentially resulting in denial of service or arbitrary code execution.

GIMP +1 vulnerability rce dos linux heap-overflow
2t 1c
high threat

CVE-2026-58380: GIMP PNM Parser Off-by-One Error Leads to RCE

A high-severity off-by-one error, CVE-2026-58380, in GIMP's PNM file format parser (specifically the `pnmscanner_gettoken()` function) allows an attacker to corrupt memory by crafting a malicious PNM file, potentially leading to denial of service or arbitrary code execution when the file is opened.

exploited GIMP +4 vulnerability memory-corruption buffer-overflow linux
1c
low advisory

Potential Proxy Execution via Systemd-run on Linux

This brief details how attackers may leverage the `systemd-run` utility on Linux systems for defense evasion and execution by running commands as detached, transient services or scopes to obscure their activities and parent-child process chains.

Acronis Cyber Protect +46 defense-evasion execution linux
1r 3t
high advisory

CVE-2026-58379: GIMP Heap Buffer Overflow in PSP Parser Allows RCE

A heap buffer overflow vulnerability (CVE-2026-58379) in GIMP's Paint Shop Pro (PSP) file format parser allows a remote attacker to achieve arbitrary code execution or cause a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file, exploiting incorrect buffer size calculations when processing low bit-depth images.

GIMP +1 heap-buffer-overflow vulnerability image-processing
3t 1c