libvips 是一款快速且内存需求较低的图片处理库。在 8.18.3 版本之前,当 libvips 使用 libultrahdr 支持构建时,在通过 VipsForeignSaveUhdr 编码增益图(gain map)的过程中,如果处理管线将输入的 JPEG 图像扩展至非常大的尺寸,libvips/foreign/uhdrsave.c 文件中的 vips_foreign_save_uhdr_set_raw_hdr 函数可能会错误地计算输出缓冲区的大小。这种缓冲区分配过小可能导致堆缓冲区越界读取,从而可能泄露相邻
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-69242 | 8.4 HIGH | libvips: Integer overflow leading to heap buffer overflow leading to possible attacker-con |
| CVE-2026-70651 | 6.9 MEDIUM | libvips: Possible integer overflow when reading multi-page TIFF images via ImageMagick |
| CVE-2026-70654 | 5.8 MEDIUM | libvips: A well-crafted PPM image processed via a custom source could lead to possible hea |
| CVE-2026-70653 | 4.8 MEDIUM | libvips: Possible heap-based buffer read overflow when decoding a well-crafted RLE Radianc |
No comments yet