← Späť na vyhľadávanie CVE

CVE-2026-6491

libvips

Popis

A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function im_minpos_vec of the file libvips/deprecated/vips7compat.c of the component nip2 Handler. Such manipulation of the argument n leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The vendor confirms that they will -be removing the deprecated area in libvips 8.19-.

CVSS 5.3EPSS 0.16%Riziko 0.54
Zobraziť zdroj
Zverejnené
2026-04-17 14:16:35
Dotknuté verzie
<8.18.3
Typ
Package
Vektor
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L