CVE-2026-70652
⚪ Do wiadomości
Błąd w libvips umożliwia przepełnienie bufora, co może ujawniać dane lub powodować awarię.
CVSS
0.0
EPSS
0.1%
Exploit
none
Vendor
Opis źródłowy (NVD)
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming JPEG to a very large output before encoding a gain map through VipsForeignSaveUhdr. The undersized allocation can cause a heap buffer over-read that may disclose adjacent data or crash the process. This issue is fixed in version 8.18.3.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.1% |
| Opublikowano (NVD) | 2026-08-20 21:17:08 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-21 22:16:43 UTC |
Referencje
- https://github.com/libvips/libvips/commit/cff17794f0698a4f47c74bb31c9700b2c83252a8 (security-advisories@github.com)
- https://github.com/libvips/libvips/pull/5039 (security-advisories@github.com)
- https://github.com/libvips/libvips/releases/tag/v8.18.3 (security-advisories@github.com)
- https://github.com/libvips/libvips/security/advisories/GHSA-h27h-jf9v-m8rg (security-advisories@github.com)