ThreatCluster

Multiple CVEs Identified in GIFLIB Affecting Remote Systems

First seen 18 Feb 2026, 15:24 UTC Api.Msrc.Microsoft 39

Article Content

Browse articles
ThreatCluster

Two vulnerabilities have been reported in GIFLIB, affecting versions 5.1.4 and 5.2.1. CVE-2021-40633 involves a memory leak in gif2rgb that can lead to denial of service, while CVE-2022-28506 is a heap-buffer-overflow in the same function that could potentially allow for exploitation. Both vulnerabilities could impact systems processing GIF files.

Timeline

2022-04-25
CVE-2022-28506 published
2022-06-14
CVE-2021-40633 published
2026-02-18
Information published about both CVEs