PT-2026-39852 · Libcaca+2 · Libcaca+2

Gh05T-1337

+2

·

Published

2026-05-11

·

Updated

2026-05-28

·

CVE-2026-42046

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libcaca versions 0.99.beta20 and earlier
Description An integer overflow in the canvas import functionality allows an attacker to cause a controlled heap out-of-bounds write (heap overflow) by supplying a crafted file in the "caca" format. Depending on the build configuration and memory allocator, this may lead to memory corruption or remote code execution.
Recommendations Apply the fix provided in commit fb77acff9ba6bb01d53940da34fb10f20b156a23.

Exploit

Fix

RCE

Integer Overflow

Heap Based Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2026-42046
OPENSUSE-SU-2026:10834-1
USN-8318-1

Affected Products

Linuxmint
Ubuntu
Libcaca