Description
A vulnerability was detected in libvips 8.19.0. This affects the function vips_bandrank_build of the file libvips/conversion/bandrank.c. Performing a manipulation of the argument index results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit is now public and may be used. The patch is named fd28c5463697712cb0ab116a2c55e4f4d92c4088. It is suggested to install a patch to address this issue.
Problem types
Timeline
| 2026-02-26: | Advisory disclosed |
| 2026-02-26: | VulDB entry created |
| 2026-02-26: | VulDB entry last update |
Credits
Niebelungen (VulDB User)
References
vuldb.com/?id.348010 (VDB-348010 | libvips bandrank.c vips_bandrank_build heap-based overflow)
vuldb.com/?ctiid.348010 (VDB-348010 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.758861 (Submit #758861 | libvips 8.19.0(7fab325d2) Improper Validation of Array Index)
github.com/libvips/libvips/issues/4878
github.com/libvips/libvips/pull/4895
github.com/libvips/libvips/issues/4878
github.com/...ommit/fd28c5463697712cb0ab116a2c55e4f4d92c4088
github.com/libvips/libvips/