PT-2026-61632 · Libvips · Libvips

CVE-2026-33327

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v4.0

7.0

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions libvips versions prior to 8.18.1
Description The vipsload operation can incorrectly determine image dimensions, which leads to an integer overflow and a subsequent heap-based buffer overflow. A heap-based buffer overflow occurs when a program writes more data to a heap memory buffer than it can hold, potentially leading to crashes or arbitrary code execution.
Recommendations Update to version 8.18.1.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33327
GHSA-2FCJ-GJ27-279X

Affected Products

Libvips