Description
A vulnerability was found in libvips up to 8.18.0. This affects the function vips_foreign_load_csv_build of the file libvips/foreign/csvload.c. The manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been made public and could be used. The patch is identified as b3ab458a25e0e261cbd1788474bbc763f7435780. It is advisable to implement a patch to correct this issue.
Problem types
Timeline
| 2026-02-24: | Advisory disclosed |
| 2026-02-24: | VulDB entry created |
| 2026-02-24: | VulDB entry last update |
Credits
Niebelungen (VulDB User)
References
vuldb.com/?id.347653 (VDB-347653 | libvips csvload.c vips_foreign_load_csv_build heap-based overflow)
vuldb.com/?ctiid.347653 (VDB-347653 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.758692 (Submit #758692 | libvips 8.19.0(7fab325d2) Improper Validation of Array Index)
github.com/libvips/libvips/issues/4874
github.com/libvips/libvips/pull/4894
github.com/libvips/libvips/issues/4874
github.com/...ommit/b3ab458a25e0e261cbd1788474bbc763f7435780
github.com/libvips/libvips/