PT-2026-21413 · Libvips · Libvips
Niebelungen
·
Published
2026-02-22
·
Updated
2026-02-22
·
CVE-2026-2913
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libvips versions prior to 8.19.0
Description
A heap-based buffer overflow exists in the
vips source read to memory function within the libvips/iofuncs/source.c file. The issue is triggered by a manipulation that can be launched locally. The exploitability is described as difficult. The impact of this issue is negligible, as it only affects custom seekable sources larger than 4 GiB, and the crash occurs in user code rather than libvips itself.Recommendations
Apply patch a56feecbe9ed66521d9647ec9fbcd2546eccd7ee.
Exploit
Fix
Buffer Overflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libvips