Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-70652— libvips: Possible heap-based buffer read overflow when resizing and re-encoding a JPEG with gain map

Quick assessment

Affected
libvips libvips
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

libvips 是一款快速且内存需求较低的图片处理库。在 8.18.3 版本之前,当 libvips 使用 libultrahdr 支持构建时,在通过 VipsForeignSaveUhdr 编码增益图(gain map)的过程中,如果处理管线将输入的 JPEG 图像扩展至非常大的尺寸,libvips/foreign/uhdrsave.c 文件中的 vips_foreign_save_uhdr_set_raw_hdr 函数可能会错误地计算输出缓冲区的大小。这种缓冲区分配过小可能导致堆缓冲区越界读取,从而可能泄露相邻

CVSS 2.0 · Low EPSS 0.11% · P2

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 1

VendorProduct Version RangeStatus
libvips libvips < 8.18.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-70652

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
libvips: Possible heap-based buffer read overflow when resizing and re-encoding a JPEG with gain map
Source: CVE Program / CVE List V5
Vulnerability Description
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming JPEG to a very large output before encoding a gain map through VipsForeignSaveUhdr. The undersized allocation can cause a heap buffer over-read that may disclose adjacent data or crash the process. This issue is fixed in version 8.18.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
缓冲区上溢读取
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
libvips libvips < 8.18.3 -

II. Public POCs for CVE-2026-70652

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-70652

登录查看更多情报信息。

Patches & Fixes for CVE-2026-70652 (2)

Vendor Advisories for CVE-2026-70652 (1)

Vendor Pages for CVE-2026-70652 (1)

Same Patch Batch · libvips · 2026-08-20 · 5 CVEs total

CVE-2026-69242 8.4 HIGH libvips: Integer overflow leading to heap buffer overflow leading to possible attacker-con
CVE-2026-70651 6.9 MEDIUM libvips: Possible integer overflow when reading multi-page TIFF images via ImageMagick
CVE-2026-70654 5.8 MEDIUM libvips: A well-crafted PPM image processed via a custom source could lead to possible hea
CVE-2026-70653 4.8 MEDIUM libvips: Possible heap-based buffer read overflow when decoding a well-crafted RLE Radianc

IV. Related Vulnerabilities

V. Comments for CVE-2026-70652

No comments yet


Leave a comment