PT-2026-21326 · Sail · Sail

Nicoppida

·

Published

2026-02-20

·

Updated

2026-03-02

·

CVE-2026-27168

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAIL (affected versions not specified)
Description SAIL is a cross-platform library used for loading and saving images, supporting animation, metadata, and ICC profiles. The software contains a flaw due to the XWD parser's handling of the bytes per line value. This value, read directly from a file using the io->strict read() function, is used as the read size without validation against the destination buffer's size. An attacker can exploit this by providing a specially crafted XWD file with a large bytes per line value, leading to a heap-based buffer overflow during a write operation beyond the allocated memory for image pixels.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

DoS

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-27168
GHSA-3G38-X2PJ-MV55

Affected Products

Sail