Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42500

Опубликовано: 29 мая 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.

A flaw was found in golang.org/x/image/bmp. A remote attacker could exploit this vulnerability by providing a specially crafted paletted BMP (Bitmap) file. Decoding this file with an out-of-range palette index causes the application to panic when accessing invalid image pixels, leading to a Denial of Service (DoS). This could make the affected application unavailable to legitimate users.

Отчет

A flaw was found in golang.org/x/image/bmp. Decoding a specially crafted paletted BMP file with an out-of-range palette index causes an unrecoverable panic, resulting in denial of service. The vulnerable code is registered automatically via init() when the bmp package is imported. Versions of golang.org/x/image prior to v0.40.0 are affected.

Меры по смягчению последствий

No mitigation is available for this vulnerability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1285
https://bugzilla.redhat.com/show_bug.cgi?id=2483431golang.org/x/image/bmp: golang: golang.org/x/image/bmp: Denial of Service via out-of-range palette index in BMP decoding

EPSS

Процентиль: 31%
0.00384
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.

CVSS3: 5.3
nvd
3 месяца назад

Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.

CVSS3: 5.3
debian
3 месяца назад

Decoding a paletted BMP file with an out-of-range palette index result ...

CVSS3: 5.3
github
3 месяца назад

Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.

suse-cvrf
24 дня назад

Security update for rclone

EPSS

Процентиль: 31%
0.00384
Низкий

6.5 Medium

CVSS3