Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33327

Опубликовано: 20 июл. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

libvips is a fast image processing library with low memory needs. The vipsload operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.

A flaw was found in libvips, an image processing library. The vipsload operation, responsible for loading images, could incorrectly calculate image dimensions. This error leads to an integer overflow, which subsequently causes a heap-based buffer overflow. A local attacker with low privileges could exploit this vulnerability to execute arbitrary code or cause the application to crash, leading to a denial of service.

Отчет

Important: A heap-based buffer overflow flaw in libvips' vipsload operation allows a local attacker with low privileges to achieve arbitrary code execution or cause a denial of service. This vulnerability arises from incorrect image dimension calculations, leading to an integer overflow. The impact is significant due to the potential for code execution, even with limited access.

Дополнительная информация

Статус:

Important
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2502892libvips: libvips: Arbitrary code execution via heap-based buffer overflow in vipsload

EPSS

Процентиль: 3%
0.00132
Низкий

7.3 High

CVSS3

Связанные уязвимости

ubuntu
30 дней назад

libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.

nvd
30 дней назад

libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.

debian
30 дней назад

libvips is a fast image processing library with low memory needs. The ...

EPSS

Процентиль: 3%
0.00132
Низкий

7.3 High

CVSS3