Unknown · Serenityos · CVE-2026-94030
**Name of the Vulnerable Software and Affected Versions**
SerenityOS versions up to 3d83e4509fd20d7438e1ae8470ffe668c136229c
**Description**
An integer overflow occurs in the `decode bmp pixel data()` function within the `Userland/Libraries/LibGfx/ImageFormats/BMPLoader.cpp` file of the LibGfx component. This issue is triggered by the manipulation of the `height` argument and can be exploited remotely, although the attack complexity is high and exploitation is considered difficult.
**Recommendations**
Apply patch 007041bb2dd6d140c9e707caddfb0a49ecf96469 to resolve the issue.