libvips 是一个高性能、低内存占用的图像处理库。在 8.18.3 版本之前,通过 VipsForeignLoadTiff 处理的特制多波段 TIFF 文件可以绕过 libvips/iofuncs/image.c 中的扫描线验证,导致 vips_image_sanity 函数中出现整数溢出。由此引发的缓冲区区域计算可能访问 mmap 驻留分配中由攻击者控制的负偏移量,从而允许读取或写入其他图像数据。这可能通过未压缩的 .v 输出导致数据泄露,并极有可能引发进程崩溃。虽然尚未证实可远程执行代码,但不能完全排除该可
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-70651 | 6.9 MEDIUM | libvips: Possible integer overflow when reading multi-page TIFF images via ImageMagick |
| CVE-2026-70654 | 5.8 MEDIUM | libvips: A well-crafted PPM image processed via a custom source could lead to possible hea |
| CVE-2026-70653 | 4.8 MEDIUM | libvips: Possible heap-based buffer read overflow when decoding a well-crafted RLE Radianc |
| CVE-2026-70652 | 2.0 LOW | libvips: Possible heap-based buffer read overflow when resizing and re-encoding a JPEG wit |
No comments yet