CVE-2026-23868 PUBLISHED

Assigner: Meta
Reserved: 16.01.2026 Published: 10.03.2026 Updated: 11.03.2026

Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.

Product Status

Vendor giflib
Product giflib
Versions Default: affected
  • affected from 5.0.0 to 6.1.1 (incl.)

References

Problem Types

  • CWE-415: Double Free