PatchSiren

GNOME CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH GNOME CVE published 2026-09-25

CVE-2026-91841

A local unprivileged user can exploit a flaw in NetworkManager-vpnc by injecting a newline character into the CA-File path, allowing execution of arbitrary commands as the root user, leading to local privilege escalation. This vulnerability, tracked as CVE-2026-91841, affects systems using NetworkManager-vpnc, particularly those with unprivileged local users. The flaw enables an attacker to execute arbitr [truncated]

HIGH GNOME CVE published 2026-09-25

CVE-2026-91840

A local unprivileged user can escalate privileges to root in NetworkManager-vpnc by injecting a newline character into the VPN username field, allowing execution of an arbitrary program with root privileges when the malicious VPN connection is activated. This vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. System administrators and security teams should assess exposure and priori [truncated]

HIGH GNOME CVE published 2026-09-25

CVE-2026-91839

A flaw in NetworkManager-fortisslvpn's FortiSSLVPN plugin allows a local unprivileged user to craft a malicious VPN profile, potentially leading to arbitrary code execution with root privileges when the profile is activated. This vulnerability, CVE-2026-91839, is a high-severity issue that system administrators and security teams should address by assessing exposure and prioritizing remediation. The vulne [truncated]

HIGH GNOME CVE published 2026-09-25

CVE-2026-91838

A local unprivileged user can exploit a flaw in NetworkManager-sstp by embedding shell metacharacters into VPN connection profile fields, allowing execution of arbitrary commands with elevated permissions when a malicious VPN connection is activated. This vulnerability affects NetworkManager-sstp installations and requires verification of vulnerable systems, restriction of user access, and monitoring for [truncated]

HIGH GNOME CVE published 2026-09-25

CVE-2026-91837

A local unprivileged user can exploit a vulnerability in NetworkManager-iodine, the iodine VPN plugin for NetworkManager, by embedding shell metacharacters in the 'nameserver' value when establishing an iodine VPN connection. This allows injection and execution of arbitrary commands with root privileges before the application drops its elevated permissions, leading to local privilege escalation.

MEDIUM GNOME CVE published 2026-09-25

CVE-2026-97222

A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML parser can dereference a freed sheet-object component, causing Gnumeric to crash. This issue affects Gnumeric installations and defenders should assess exposure and prioritize patching or applying workarounds to prevent potential crashes of the Gnumer [truncated]

MEDIUM GNOME CVE published 2026-08-24

CVE-2026-78475

A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read. This can result in a denial of service due to stack exhaustion and a limited information disclosure of stack memory contents int [truncated]

HIGH GNOME CVE published 2026-07-27

CVE-2026-66759

A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues reading past the bounds of the buffer. This out-of-bounds read vulnerability results in i [truncated]

MEDIUM GNOME CVE published 2026-07-27

CVE-2026-66757

A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both dimensions to their maximum value (65535), the multiplication ysize * zsize overflows the standard 32-bit int boundary before being passed to calloc. This in [truncated]

MEDIUM GNOME CVE published 2026-07-22

CVE-2026-16615

CVE-2026-16615 is a medium-severity vulnerability in librest's PKCE implementation for OAuth authorization. The flaw uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. This results in a generated 'code verifier' that lacks sufficient cryptographic entropy, allowing a malicious actor to reverse-engineer the pseudo-random number generator (PRNG) seed to p [truncated]

MEDIUM GNOME CVE published 2026-06-30

CVE-2026-58013

A buffer over-read vulnerability was found in GLib's g_io_channel_read_line_backend() function. This issue occurs when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. The vulnerability can lead to a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.

MEDIUM GNOME CVE published 2026-06-30

CVE-2026-58012

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-30T13:19:17.330Z and has not been modified since then. The g_regex_replace function in GLib is vulnerable to a buffer over-read when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes. This can cause a denial of service and potentially disclose 1-5 bytes of information. The [truncated]

HIGH GNOME CVE published 2026-06-22

CVE-2026-6653

CVE-2026-6653 is a Use After Free vulnerability in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0. A remote attacker can cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling. This CVE was published on 2026-06-22 and has a CVSS score of 7, indicating a High severity. Defenders should assess their exposure and prioritize patching.

MEDIUM GNOME CVE published 2026-06-17

CVE-2026-2604

A flaw in evolution-data-server allows a Flatpak application with D-Bus access to delete arbitrary files on the host filesystem by crafting a malicious URI. This issue is rated as MEDIUM with a CVSS score of 5.6. The vulnerability arises from inconsistent comparison logic in the addressbook file backend, which enables a Flatpak application to potentially delete critical system files, elevate privileges, a [truncated]

HIGH GNOME CVE published 2026-01-29

CVE-2020-37011

A heap corruption vulnerability exists in GNOME Fonts Viewer 3.34.0 that can be triggered through maliciously crafted TTF font files. The vulnerability involves an out-of-bounds write condition that attackers may exploit by supplying a specially crafted font with an oversized pattern, leading to memory exhaustion through repeated memory allocation calls and potential process crash. The CVSS 4.0 vector ind [truncated]

MEDIUM Gnome CVE published 2017-02-03

CVE-2016-6163

CVE-2016-6163 is a denial-of-service vulnerability in librsvg2 2.40.2. NVD describes the flaw as an out-of-bounds read in rsvg_pattern_fix_fallback in rsvg-paint_server.c, reachable through a crafted SVG file. The weakness is classified as CWE-125, and NVD rates the impact as availability-only loss with no confidentiality or integrity impact. The affected product entry in the NVD record is gnome:librsvg:2 [truncated]