PT-2021-17150 · Unknown+4 · Godot Engine+4

Hpvb

·

Published

2021-02-08

·

Updated

2025-06-18

·

CVE-2021-26825

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Godot Engine versions up to v3.2
Description: An integer overflow issue exists in the Godot Engine that can be triggered when loading specially crafted .TGA image files. The issue is located in the ImageLoaderTGA::load image() function and leads to a dynamic stack buffer overflow. Depending on the application context, the attack vector can be local or remote, potentially resulting in code execution and/or system crash.
Recommendations: For Godot Engine versions up to v3.2, consider disabling the ImageLoaderTGA::load image() function when loading .TGA image files to minimize the risk of exploitation until a patch is available. Restrict the loading of .TGA files from untrusted sources to reduce the risk of remote attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2025-5969
CVE-2021-26825
OPENSUSE-SU-2024:10813-1
OPENSUSE-SU-2024:12761-1
USN-7579-1

Affected Products

Alt Linux
Debian
Godot Engine
Linuxmint
Ubuntu