Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-35591

Опубликовано: 20 июл. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

libvips is a fast image processing library with low memory needs. The tiffload operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.

A flaw was found in libvips, an image processing library. The tiffload operation, which handles loading TIFF images, could incorrectly identify the number of channels in embedded JPEG or JPEG2000 tiles. This vulnerability may allow a local attacker with low privileges to trigger a buffer overflow, potentially leading to data corruption, system instability, or the disclosure of limited sensitive information.

Отчет

This flaw is rated as Important. A local attacker with low privileges could exploit a buffer overflow in libvips when processing a specially crafted TIFF image containing malformed JPEG or JPEG2000-encoded tiles. This could lead to application crashes, data corruption, or potentially arbitrary code execution, significantly impacting the integrity and availability of systems that handle untrusted image files.

Дополнительная информация

Статус:

Important
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2502881libvips: libvips: Buffer overflow via incorrect channel determination in TIFF image loading

EPSS

Процентиль: 3%
0.00132
Низкий

7.3 High

CVSS3

Связанные уязвимости

ubuntu
30 дней назад

libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.

nvd
30 дней назад

libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer overflow. This has been patched in version 8.18.2.

debian
30 дней назад

libvips is a fast image processing library with low memory needs. The ...

EPSS

Процентиль: 3%
0.00132
Низкий

7.3 High

CVSS3