PT-2026-39852 · Libcaca+3 · Libcaca+3

·

CVE-2026-42046

·

Published

2026-05-11

·

Updated

2026-07-09

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libcaca versions 0.99.beta20 and earlier
Description An integer overflow in the canvas import functionality allows an attacker to cause a controlled heap out-of-bounds write (heap overflow) by supplying a crafted file in the "caca" format. Depending on the build configuration and memory allocator, this may lead to memory corruption or remote code execution.
Recommendations Apply the fix provided in commit fb77acff9ba6bb01d53940da34fb10f20b156a23.

Exploit

Fix

RCE

DoS

Memory Corruption

Integer Overflow

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10825
CVE-2026-42046
ECHO-A932-EED9-9DA1
GHSA-4VVG-VRQV-M56W
OPENSUSE-SU-2026:10834-1
OPENSUSE-SU-2026:21101-1
SUSE-SU-2026:22175-1
SUSE-SU-2026:2394-1
SUSE-SU-2026:2423-1
SUSE-SU-2026:2424-1
USN-8318-1

Affected Products

Linuxmint
Red Os
Ubuntu
Libcaca