PT-2026-21413 · Libvips · Libvips

Niebelungen

·

Published

2026-02-22

·

Updated

2026-02-22

·

CVE-2026-2913

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libvips versions prior to 8.19.0
Description A heap-based buffer overflow exists in the vips source read to memory function within the libvips/iofuncs/source.c file. The issue is triggered by a manipulation that can be launched locally. The exploitability is described as difficult. The impact of this issue is negligible, as it only affects custom seekable sources larger than 4 GiB, and the crash occurs in user code rather than libvips itself.
Recommendations Apply patch a56feecbe9ed66521d9647ec9fbcd2546eccd7ee.

Exploit

Fix

Buffer Overflow

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2913

Affected Products

Libvips