PT-2026-79142 · Libvips · Libvips

CVE-2026-70652

·

Published

2026-08-20

·

Updated

2026-08-21

CVSS v4.0

2.0

Low

VectorAV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions libvips versions prior to 8.18.3
Description When built with libultrahdr support, the library can incorrectly size an output buffer within the vips foreign save uhdr set raw hdr() function in libvips/foreign/uhdrsave.c. This occurs when a pipeline enlarges an incoming JPEG to a very large output before encoding a gain map through VipsForeignSaveUhdr. The resulting undersized allocation can lead to a heap buffer over-read, which may cause a process crash or the disclosure of adjacent data.
Recommendations Update to version 8.18.3.

Exploit

Fix

Buffer Over-read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-70652
GHSA-H27H-JF9V-M8RG

Affected Products

Libvips