Gnoppix Security Announcement - 2026-08-01T08:01:13.357-04:00

Gnoppix Security Update: Critical libgd2 Flaw Patched

GSA-6409-1 addresses a severe vulnerability in the libgd2 graphics library. The flaw could allow remote attackers to execute arbitrary code or cause a denial of service. Users must update immediately.

Affected Systems

  • Gnoppix 23/25 (oldstable)
  • Gnoppix 25 (stable)

All versions of libgd2 shipped with these releases are vulnerable.

Vulnerability Details

The issue stems from improper input validation in the library’s image processing routines. An attacker can trigger a heap-based buffer overflow by sending a specially crafted image file.

Successful exploitation requires no authentication. Systems processing untrusted images are at highest risk.

How to Fix

Upgrade the libgd2 package to the patched version.

Action required: Run apt update && apt upgrade on all affected systems.

No workarounds exist. The update is the only mitigation.

Background

libgd2 is a widely used library for creating and manipulating PNG, JPEG, and GIF images. This vulnerability was discovered internally and has no known active exploits. Gnoppix Security recommends applying the update as a standard security measure. - Please update your systems.