Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-33809

Опубликовано: 25 мар. 2026
Источник: debian
EPSS Низкий

Описание

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-golang-x-imagefixed0.38.0-1package
golang-golang-x-imageno-dsatrixiepackage
golang-golang-x-imageno-dsabookwormpackage
golang-golang-x-imagepostponedbullseyepackage

Примечания

  • https://github.com/golang/go/issues/78267

  • Fixed by: https://github.com/golang/image/commit/23ae9ed61c1d3343fb95015810f62dcbf444976e (v0.38.0)

EPSS

Процентиль: 25%
0.00328
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

CVSS3: 6.5
redhat
4 месяца назад

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

CVSS3: 5.3
nvd
4 месяца назад

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excessive resource consumption or an out-of-memory error.

CVSS3: 5.3
github
4 месяца назад

Go Images vulnerable to an out-of-memory error via a crafted TIFF file

CVSS3: 5.3
fstec
4 месяца назад

Уязвимость библиотеки golang.org/x/image/tiff языка программирования Go, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 25%
0.00328
Низкий