CVE-2026-77118

EUVD-2026-63345
A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the Huffman delta loop advances its output pointer with q++ after every decoded delta and never checks it against the end of the heap-allocated luma/chroma plane buffers. The pointer is repositioned only when a sync marker introduces a new plane/row; between sync markers the run length is bounded solely by the input.



A crafted PCD file that positions the pointer near the end of a plane and then supplies a long run of deltas with no intervening sync therefore walks the pointer past the end of the allocation and writes through it. Processing an untrusted PCD file — for example with gm convert or gm identify, or through any application linked against libGraphicsMagick — can corrupt heap memory beyond the buffers.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
sealCNA
8.4 HIGH
LOCAL
LOW
NONE
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
graphicsmagickgraphicsmagick
1.0.0 ≤
𝑥
< 1.3.48
CNA
graphicsmagickgraphicsmagick
𝑥
< 1.3.48
CNA
Debian logo
Debian Releases
Debian Product
Codename
graphicsmagick
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
1.4+really1.3.48-1
fixed
sid
1.4+really1.3.48-1
fixed
trixie
vulnerable