CVE-2026-69242

EUVD-2026-63651
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image.c and cause an integer overflow in vips_image_sanity. The resulting buffer-region calculation can access attacker-controlled negative offsets in mmap-resident allocations, allowing reads or writes of other image data, possible data disclosure through uncompressed .v output, and likely process crashes. Remote code execution has not been demonstrated but cannot be ruled out. This issue is fixed in version 8.18.3.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GitHub_MCNA
8.4 HIGH
LOCAL
LOW
LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 17.88%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
libvipslibvips
𝑥
< 8.18.3
CNA
Debian logo
Debian Releases
Debian Product
Codename
vips
bookworm
vulnerable
bookworm (security)
vulnerable
forky
8.18.6-2
fixed
sid
8.18.7-1
fixed
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
vips
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage