Debian Linux Security Advisory 2026-1 – Marc Schoenefeld discovered a stack-based buffer overflow in the XPM reader implementation in netpbm-free, a suite of image manipulation utilities. An attacker could cause a denial of service (application crash) or possibly execute arbitrary code via an XPM image file that contains a crafted header field associated with a large color index value.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/87989/dsa-2026-1.txt
Source: https://packetstormsecurity.com/files/87989/Debian-Linux-Security-Advisory-2026-1.html