Описание
A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the xpmNextWord() function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.
Отчет
The vulnerability is assessed as Medium severity due to its impact being limited to availability. While exploitation requires local access and low privileges, it does not require user interaction. Successful exploitation can cause applications processing XPM files to crash, which may affect batch processing systems or graphical applications. The absence of confidentiality and integrity impact reduces the overall severity, but the ease of triggering the issue still presents a reliability concern.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libXpm | Fix deferred | ||
| Red Hat Enterprise Linux 6 | libXpm | Fix deferred | ||
| Red Hat Enterprise Linux 7 | libXpm | Fix deferred | ||
| Red Hat Enterprise Linux 8 | libXpm | Fix deferred | ||
| Red Hat Enterprise Linux 9 | libXpm | Fix deferred | ||
| Red Hat Hardened Images | libxpm-main-3.5.17-7.2.hum1 | Fixed | RHSA-2026:30354 | 26.06.2026 |
| Red Hat Hardened Images | libxpm-main-3.5.19-4.hum1 | Fixed | RHSA-2026:47072 | 28.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.
A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a specially crafted or very small XPM (X PixMap) image file. This improper validation of file boundaries can cause an internal pointer to read beyond the file's end, leading to application crashes and Denial of Service conditions.
Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing
A flaw was found in libXpm. A local user with low privileges could exp ...
EPSS
5.5 Medium
CVSS3