PT-2026-36892 · Unknown · Cimg Library

Jorgebarredo14

·

Published

2026-05-04

·

Updated

2026-05-04

·

CVE-2026-42144

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions CImg Library versions prior to commit 4ca26bc
Description An integer overflow exists in the load pnm() function during the computation of WHD size. A specially crafted PNM, PGM, or PPM file containing large dimension values can cause the calculation to wrap around, bypassing the memory allocation guard. This results in the allocation of an undersized buffer, which may lead to a heap buffer overflow when processing untrusted image files.
Recommendations Update CImg Library to the version containing commit 4ca26bc.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42144

Affected Products

Cimg Library