Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mkamensky

#32027of 53,633
7.8Total CVSS
Vulnerabilities · 1
PT-2026-43475
7.8
2026-05-27
Gdal · Gdal · CVE-2026-49014
**Name of the Vulnerable Software and Affected Versions** GDAL versions 3.1.0 through 3.13.0 **Description** The netCDF driver contains a stack-based buffer overflow in the `scanForGeometryContainers()` function located in `frmts/netcdf/netcdfsg.cpp`. The issue occurs because the function reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. An attacker can exploit this by using a crafted NetCDF file containing an oversized geometry attribute to achieve arbitrary code execution on the server running the software. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.