Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-69242— libvips: Integer overflow leading to heap buffer overflow leading to possible attacker-controlled mmap-resident write

Quick assessment

Affected
libvips libvips
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

libvips 是一个高性能、低内存占用的图像处理库。在 8.18.3 版本之前,通过 VipsForeignLoadTiff 处理的特制多波段 TIFF 文件可以绕过 libvips/iofuncs/image.c 中的扫描线验证,导致 vips_image_sanity 函数中出现整数溢出。由此引发的缓冲区区域计算可能访问 mmap 驻留分配中由攻击者控制的负偏移量,从而允许读取或写入其他图像数据。这可能通过未压缩的 .v 输出导致数据泄露,并极有可能引发进程崩溃。虽然尚未证实可远程执行代码,但不能完全排除该可

CVSS 8.4 · High EPSS 0.21% · P11

Possible ATT&CK Techniques 1 AI

T1200 · Hardware Additions

Affected Version Matrix 1

VendorProduct Version RangeStatus
libvips libvips < 8.18.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-69242

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
libvips: Integer overflow leading to heap buffer overflow leading to possible attacker-controlled mmap-resident write
Source: CVE Program / CVE List V5
Vulnerability Description
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image.c and cause an integer overflow in vips_image_sanity. The resulting buffer-region calculation can access attacker-controlled negative offsets in mmap-resident allocations, allowing reads or writes of other image data, possible data disclosure through uncompressed .v output, and likely process crashes. Remote code execution has not been demonstrated but cannot be ruled out. This issue is fixed in version 8.18.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
堆缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
libvips libvips < 8.18.3 -

II. Public POCs for CVE-2026-69242

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 12619 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-69242

登录查看更多情报信息。

Patches & Fixes for CVE-2026-69242 (2)

Vendor Advisories for CVE-2026-69242 (1)

Vendor Pages for CVE-2026-69242 (1)

Same Patch Batch · libvips · 2026-08-20 · 5 CVEs total

CVE-2026-70651 6.9 MEDIUM libvips: Possible integer overflow when reading multi-page TIFF images via ImageMagick
CVE-2026-70654 5.8 MEDIUM libvips: A well-crafted PPM image processed via a custom source could lead to possible hea
CVE-2026-70653 4.8 MEDIUM libvips: Possible heap-based buffer read overflow when decoding a well-crafted RLE Radianc
CVE-2026-70652 2.0 LOW libvips: Possible heap-based buffer read overflow when resizing and re-encoding a JPEG wit

IV. Related Vulnerabilities

V. Comments for CVE-2026-69242

No comments yet


Leave a comment