CVE-2026-70652

⚪ Do wiadomości

Błąd w libvips umożliwia przepełnienie bufora, co może ujawniać dane lub powodować awarię.

CVSS
0.0
EPSS
0.1%
Exploit
none
Vendor
Opis źródłowy (NVD)

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming JPEG to a very large output before encoding a gain map through VipsForeignSaveUhdr. The undersized allocation can cause a heap buffer over-read that may disclose adjacent data or crash the process. This issue is fixed in version 8.18.3.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS0.0
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.1%
Opublikowano (NVD)2026-08-20 21:17:08 UTC
Ostatnia modyfikacja (NVD)2026-08-21 22:16:43 UTC
Referencje