PT-2026-22285 · Libvips · Libvips
Niebelungen
·
Publicado
2026-02-27
·
Atualizado
2026-02-27
·
CVE-2026-3281
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libvips version 8.19.0
Description
A flaw exists in libvips that involves a heap-based buffer overflow. This occurs in the
vips bandrank build function within the libvips/conversion/bandrank.c file when the index argument is manipulated. The issue can be exploited locally. The exploit is publicly available.Recommendations
Install the patch fd28c5463697712cb0ab116a2c55e4f4d92c4088 to address this issue.
Exploit
Correção
Buffer Overflow
Heap Based Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Libvips