PT-2026-95078 · Sail · Sail
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAIL versions prior to 1.0.0
Description
A heap overwrite occurs in the
sail codec load frame v8 xbm() function within src/sail-codecs/xbm/xbm.c when processing X10 static short files. The issue arises because the decoded pixel buffer is allocated using the X11 one-byte-per-literal layout, but the decode loop writes two bytes per literal. When ceil(width/8) results in an odd row stride, the X10 literal count includes a padding byte for every row that the destination buffer cannot accommodate. This leads to a forward heap overwrite that scales with the image height when loading XBM files via sail load from file, sail load from memory, or sail start loading *. This can result in process state corruption, crashes, or potential code execution.Recommendations
Update to version 1.0.0.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sail