Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-23868

27
FAUCET Score

CVE-2026-23868 describes a double-free vulnerability within Giflib, stemming from a shallow copy in GifMakeSavedImage and improper error handling. While the specific affected products are not detailed, the conditions required to trigger this flaw are considered difficult to achieve. There is no CVSS score, EPSS, or FAUCET Risk Score provided, and no known exploit intelligence, active exploitation, or community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.0.0, <= 6.1.1CPE matchmatch criteria
cpe:2.3:a:giflib_project:giflib:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.1MEDIUM

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.4
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
4.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 3rd percentile among its peer group of 386 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

microsoftpatch availablevia msrc
Product: 19085-17084Fixed in: 5.2.1-11
microsoftpatch availablevia msrc
Product: 20204-17086Fixed in: 5.2.1-11
microsoftpatch availablevia msrc
Product: azl3 giflib 5.2.1-10 on Azure Linux 3.0Fixed in: 5.2.1-11
microsoftpatch availablevia msrc
Product: cbl2 giflib 5.2.1-10 on CBL Mariner 2.0Fixed in: 5.2.1-11
ubuntupatch availablevia ubuntu_usn
Product: giflib (noble)Fixed in: 5.2.2-1ubuntu1.2
ubuntupatch availablevia ubuntu_usn
Product: giflib (resolute)Fixed in: 5.2.2-1ubuntu3.2
ubuntupatch availablevia ubuntu_usn
Product: giflib (jammy)Fixed in: 5.1.9-2ubuntu0.3

Vendor Advisories (2)

ubuntuUSN-8583-1

GIFLIB vulnerabilities

Jul 22, 2026
microsoft2026-Mar/CVE-2026-23868Important

Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.

Mar 10, 2026

References

access.redhat.com / errata/RHSA-2026:16008
access.redhat.com / errata/RHSA-2026:16009
access.redhat.com / errata/RHSA-2026:16030
access.redhat.com / errata/RHSA-2026:16174
access.redhat.com / errata/RHSA-2026:19154
access.redhat.com / errata/RHSA-2026:19367
access.redhat.com / errata/RHSA-2026:19724
access.redhat.com / errata/RHSA-2026:19725
access.redhat.com / errata/RHSA-2026:25096
access.redhat.com / errata/RHSA-2026:8858
access.redhat.com / errata/RHSA-2026:8859
access.redhat.com / errata/RHSA-2026:8861
access.redhat.com / errata/RHSA-2026:8883
access.redhat.com / errata/RHSA-2026:8884
access.redhat.com / errata/RHSA-2026:8885
access.redhat.com / errata/RHSA-2026:8886
access.redhat.com / errata/RHSA-2026:8887
access.redhat.com / errata/RHSA-2026:9290
access.redhat.com / errata/RHSA-2026:9291
access.redhat.com / errata/RHSA-2026:9292
access.redhat.com / errata/RHSA-2026:9294
access.redhat.com / errata/RHSA-2026:9295
access.redhat.com / security/cve/CVE-2026-23868
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-23868.json
sourceforge.net / p/giflib/code/ci/f5b7267aed3665ef025c13823e454170d031c106/tree/gifalloc.c
Patch
facebook.com / security/advisories/cve-2026-23868
Third Party Advisory