PT-2026-79140 · Libvips · Libvips
CVE-2026-69242
·
Published
2026-08-20
·
Updated
2026-08-20
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
libvips versions prior to 8.18.3
Description
A crafted many-band TIFF image processed through the
VipsForeignLoadTiff function can bypass scanline validation in libvips/iofuncs/image.c, leading to an integer overflow in the vips image sanity() function. This results in a buffer-region calculation that allows access to attacker-controlled negative offsets in mmap-resident allocations. This behavior can lead to the reading or writing of other image data, potential data disclosure via uncompressed .v output, and process crashes.Recommendations
Update to version 8.18.3.
Exploit
Fix
Integer Overflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libvips