CVE-2026-3282

EUVD-2026-8989
A flaw has been found in libvips 8.19.0. This vulnerability affects the function vips_unpremultiply_build of the file libvips/conversion/unpremultiply.c. Executing a manipulation of the argument alpha_band can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been published and may be used. This patch is called 7215ead1e0cd7d3703cc4f5fca06d7d0f4c22b91. A patch should be applied to remediate this issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 12.3%
Affected Products (NVD)
VendorProductVersion
libvipslibvips
8.19.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
vips
bookworm
8.14.1-3+deb12u3
fixed
bookworm (security)
vulnerable
bullseye
postponed
bullseye (security)
vulnerable
forky
8.18.5-1
fixed
sid
8.18.5-1
fixed
trixie
8.16.1-1+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
vips
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
ignored