- What: A security update for giflib addresses a buffer overflow vulnerability that could lead to denial of service
- Impact: Affected systems include Red Hat Enterprise Linux 9.4 and 9.4 SUSE
Red Hat Product Errata RHSA-2026:33452 - Security Advisory Issued: 2026-06-30 Updated: 2026-06-30 RHSA-2026:33452 - Security Advisory Overview Updated Packages Synopsis Important: giflib security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for giflib is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description giflib is a library for reading and writing gif images. Security Fix(es): giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension (CVE-2026-26740) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x Fixes BZ - 2448747 - CVE-2026-26740 giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension CVEs CVE-2026-26740 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.4 SRPM giflib-5.2.1-9.el9_4.2.src.rpm SHA-256: 71c158281081a423f74583e1d3383baea62c561d06834073c702eef5cfefd054 x86_64 giflib-5.2.1-9.el9_4.2.i686.rpm SHA-256: 09fcb989bb7163123e3789d59a80ced17c02b4780a10516a231a1d65f31107bd giflib-5.2.1-9.el9_4.2.x86_64.rpm SHA-256: af84406459d81e79ed8eda1873d2dc5342d93844c151f759827cf7cca8ce4052 giflib-debuginfo-5.2.1-9.el9_4.2.i686.rpm SHA-256: d55de16f19ba3a1c1debbab6298a6823a6daf2ebe6a0772b2ae660bb472513fd giflib-debuginfo-5.2.1-9.el9_4.2.x86_64.rpm SHA-256: 4938de57a0dc23a2dd69065ca23f1e17f12c24a7ce77dc48b639c0b87271b859 giflib-debugsource-5.2.1-9.el9_4.2.i686.rpm SHA-256: a64fafe48f6471f2e79d1974d2bd7f3658790c98bad0b7e4e1bda22082e222c5 giflib-debugsource-5.2.1-9.el9_4.2.x86_64.rpm SHA-256: 3ea327dd50ffedeaf01c9f4ee3268ea00bbddd2e361f0e4f4527f1c0e3af1fcf giflib-utils-debuginfo-5.2.1-9.el9_4.2.i686.rpm SHA-256: 1d0eef92f592bd769695b0eac681299c57c20dd2610b8ef9ed90501418f03701 giflib-utils-debuginfo-5.2.1-9.el9_4.2.x86_64.rpm SHA-256: 5f529ba86f2111a173e8a4f21039290e276d31f21275e473414d9f59869948e2 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 SRPM giflib-5.2.1-9.el9_4.2.src.rpm SHA-256: 71c158281081a423f74583e1d3383baea62c561d06834073c702eef5cfefd054 ppc64le giflib-5.2.1-9.el9_4.2.ppc64le.rpm SHA-256: ab8c2d2c5ad57a9c2536547aca352fdfdc077db6abbaa898a7330f2ca1460c9d giflib-debuginfo-5.2.1-9.el9_4.2.ppc64le.rpm SHA-256: c9663d80ccb69435a94a41e96f940e7307afa86cb1a29ef9a707d893db94fc96 giflib-debugsource-5.2.1-9.el9_4.2.ppc64le.rpm SHA-256: 5136eabeecb25565d7c49403da82f40fb241323ef6ce9573dd7aa50edb1938ef giflib-utils-debuginfo-5.2.1-9.el9_4.2.ppc64le.rpm SHA-256: f39817aba3397e26f7ef3f64851e3292e0fc40a27bd5c9175097eb96371b3546 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 SRPM giflib-5.2.1-9.el9_4.2.src.rpm SHA-256: 71c158281081a423f74583e1d3383baea62c561d06834073c702eef5cfefd054 x86_64 giflib-5.2.1-9.el9_4.2.i686.rpm SHA-256: 09fcb989bb7163123e3789d59a80ced17c02b4780a10516a231a1d65f31107bd giflib-5.2.1-9.el9_4.2.x86_64.rpm SHA-256: af84406459d81e79ed8eda1873d2dc5342d93844c151f759827cf7cca8ce4052 giflib-debuginfo-5.2.1-9.el9_4.2.i686.rpm SHA-256: d55de16f19ba3a1c1debbab6298a6823a6daf2ebe6a0772b2ae660bb472513fd giflib-debuginfo-5.2.1-9.el9_4.2.x86_64.rpm SHA-256: 4938de57a0dc23a2dd69065ca23f1e17f12c24a7ce77dc48b639c0b87271b859 giflib-debugsource-5.2.1-9.el9_4.2.i686.rpm SHA-256: a64fafe48f6471f2e79d1974d2bd7f3658790c98bad0b7e4e1bda22082e222c5 giflib-debugsource-5.2.1-9.el9_4.2.x86_64.rpm SHA-256: 3ea327dd50ffedeaf01c9f4ee3268ea00bbddd2e361f0e4f4527f1c0e3af1fcf giflib-utils-debuginfo-5.2.1-9.el9_4.2.i686.rpm SHA-256: 1d0eef92f592bd769695b0eac681299c57c20dd2610b8ef9ed90501418f03701 giflib-utils-debuginfo-5.2.1-9.el9_4.2.x86_64.rpm SHA-256: 5f529ba86f2111a173e8a4f21039290e276d31f21275e473414d9f59869948e2 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 SRPM giflib-5.2.1-9.el9_4.2.src.rpm SHA-256: 71c158281081a423f74583e1d3383baea62c561d06834073c702eef5cfefd054 aarch64 giflib-5.2.1-9.el9_4.2.aarch64.rpm SHA-256: 256877405939178a2cc53aa311747c757ddebf9e54298f6a052d2b7bfcf15bd9 giflib-debuginfo-5.2.1-9.el9_4.2.aarch64.rpm SHA-256: d4d655fa30b7b6ad16eefa8f006e554324179d81e17a4de819cacaa483517177 giflib-debugsource-5.2.1-9.el9_4.2.aarch64.rpm SHA-256: 8f3074b62ae3bb9d5cd1037d177ee93e259e677f70448a98c6dcb682ebd343db giflib-utils-debuginfo-5.2.1-9.el9_4.2.aarch64.rpm SHA-256: d23534f1d7c80b510bd4605b8975bfd4f1329b11a9d4109548876a27eb827655 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 SRPM giflib-5.2.1-9.el9_4.2.src.rpm SHA-256: 71c158281081a423f74583e1d3383baea62c561d06834073c702eef5cfefd054 s390x giflib-5.2.1-9.el9_4.2.s390x.rpm SHA-256: 7bc76edb9a276f1f72b8b69f9ef52bd02346e2c4f313d18d21ba5ad27fb6f541 giflib-debuginfo-5.2.1-9.el9_4.2.s390x.rpm SHA-256: 1390cb1ce099ec56735d9c435480ceda39534326f54601ab4a202e82042a2010 giflib-debugsource-5.2.1-9.el9_4.2.s390x.rpm SHA-256: ed37efcb32125b93de316e8dd9184c688a255e1e92c24fdafd222e1ee2aaec4e giflib-utils-debuginfo-5.2.1-9.el9_4.2.s390x.rpm SHA-256: 54ab3a95b0f262dba93e684c5681fd5e608da19b7f2458ebc6997360106d9d43 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 SRPM giflib-5.2.1-9.el9_4.2.src.rpm SHA-256: 71c158281081a423f74583e1d3383baea62c561d06834073c702eef5cfefd054 x86_64 giflib-5.2.1-9.el9_4.2.i686.rpm SHA-256: 09fcb989bb7163123e3789d59a80ced17c02b4780a10516a231a1d65f31107bd giflib-5.2.1-9.el9_4.2.x86_64.rpm SHA-256: af84406459d81e79ed8eda1873d2dc5342d93844c151f759827cf7cca8ce4052 giflib-debuginfo-5.2.1-9.el9_4.2.i686.rpm SHA-256: d55de16f19ba3a1c1debbab6298a6823a6daf2ebe6a0772b2ae660bb472513fd giflib-debuginfo-5.2.1-9.el9_4.2.x86_64.rpm SHA-256: 4938de57a0dc23a2dd69065ca23f1e17f12c24a7ce77dc48b639c0b87271b859 giflib-debugsource-5.2.1-9.el9_4.2.i686.rpm SHA-256: a64fafe48f6471f2e79d1974d2bd7f3658790c98bad0b7e4e1bda22082e222c5 giflib-debugsource-5.2.1-9.el9_4.2.x86_64.rpm SHA-256: 3ea327dd50ffedeaf01c9f4ee3268ea00bbddd2e361f0e4f4527f1c0e3af1fcf giflib-utils-debuginfo-5.2.1-9.el9_4.2.i686.rpm SHA-256: 1d0eef92f592bd769695b0eac681299c57c20dd2610b8ef9ed90501418f03701 giflib-utils-debuginfo-5.2.1-9.el9_4.2.x86_64.rpm SHA-256: 5f529ba86f2111a173e8a4f21039290e276d31f21275e473414d9f59869948e2 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 SRPM giflib-5.2.1-9.el9_4.2.src.rpm SHA-256: 71c158281081a423f74583e1d3383baea62c561d06834073c702eef5cfefd054 aarch64 giflib-5.2.1-9.el9_4.2.aarch64.rpm SHA-256: 256877405939178a2cc53aa311747c757ddebf9e54298f6a052d2b7bfcf15bd9 giflib-debuginfo-5.2.1-9.el9_4.2.aarch64.rpm SHA-256: d4d655fa30b7b6ad16eefa8f006e554324179d81e17a4de819cacaa483517177 giflib-debugsource-5.2.1-9.el9_4.2.aarch64.rpm SHA-256: 8f3074b62ae3bb9d5cd1037d177ee93e259e677f70448a98c6dcb682ebd343db giflib-utils-debuginfo-5.2.1-9.el9_4.2.aarch64.rpm SHA-256: d23534f1d7c80b510bd4605b8975bfd4f1329b11a9d4109548876a27eb827655 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 SRPM giflib-5.2.1-9.el9_4.2.src.rpm SHA-256: 71c158281081a423f74583e1d3383baea62c561d06834073c702eef5cfefd054 ppc64le giflib-5.2.1-9.el9_4.2.ppc64le.rpm SHA-256: ab8c2d2c5ad57a9c2536547aca352fdfdc077db6abbaa898a7330f2ca1460c9d giflib-debuginfo-5.2.1-9.el9_4.2.ppc64le.rpm SHA-256: c9663d80ccb69435a94a41e96f940e7307afa86cb1a29ef9a707d893db94fc96 giflib-debugsource-5.2.1-9.el9_4.2.ppc64le.rpm SHA-256: 5136eabeecb25565d7c49403da82f40fb241323ef6ce9573dd7aa50edb1938ef giflib-utils-debuginfo-5.2.1-9.el9_4.2.ppc64le.rpm SHA-256: f39817aba3397e26f7ef3f64851e3292e0fc40a27bd5c9175097eb96371b3546 Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 SRPM giflib-5.2.1-9.el9_4.2.src.rpm SHA-256: 71c158281081a423f74583e1d3383baea62c561d06834073c702eef5cfefd054 s390x giflib-5.2.1-9.el9_4.2.s390x.rpm SHA-256: 7bc76edb9a276f1f72b8b69f9ef52bd02346e2c4f313d18d21ba5ad27fb6f541 giflib-debuginfo-5.2.1-9.el9_4.2.s390x.rpm SHA-256: 1390cb1ce099ec56735d9c435480ceda39534326f54601ab4a202e82042a2010 giflib-debugsource-5.2.1-9.el9_4.2.s390x.rpm SHA-256: ed37efcb32125b93de316e8dd9184c688a255e1e92c24fdafd222e1ee2aaec4e giflib-utils-debuginfo-5.2.1-9.el9_4.2.s390x.rpm SHA-256: 54ab3a95b0f262dba93e684c5681fd5e608da19b7f2458ebc6997360106d9d43 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .