ELA-1805-1 libgd2 security update

denial of service or arbitrary code execution

2026-08-12
Packagelibgd2
Version2.2.4-2+deb9u7 (stretch), 2.2.5-5.2+deb10u2 (buster)
Related CVEs CVE-2026-9672


A vulnerability was discovered in libgd2, a library for programmatic graphics creation and manipulation, which may result in denial of service or potentially the execution of arbitrary code if a malformed GIF file is processed.



For Debian 10 buster, these problems have been fixed in version 2.2.5-5.2+deb10u2.

For Debian 9 stretch, these problems have been fixed in version 2.2.4-2+deb9u7.

We recommend that you upgrade your libgd2 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.