CVE-2026-69242

NameCVE-2026-69242
Descriptionlibvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image.c and cause an integer overflow in vips_image_sanity. The resulting buffer-region calculation can access attacker-controlled negative offsets in mmap-resident allocations, allowing reads or writes of other image data, possible data disclosure through uncompressed .v output, and likely process crashes. Remote code execution has not been demonstrated but cannot be ruled out. This issue is fixed in version 8.18.3.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
vips (PTS)bullseye8.10.5-2vulnerable
bullseye (security)8.10.5-2+deb11u1vulnerable
bookworm8.14.1-3+deb12u3vulnerable
bookworm (security)8.14.1-3+deb12u2vulnerable
trixie8.16.1-1+deb13u1vulnerable
forky, sid8.18.5-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
vipssource(unstable)8.18.3-1

Notes

https://github.com/libvips/libvips/security/advisories/GHSA-9rwc-f68v-4482
https://github.com/libvips/libvips/pull/5012
Fixed by: https://github.com/libvips/libvips/commit/c72f50927413cd2451837d9813f954bc5d88f548 (v8.18.3-rc1)

Search for package or bug name: Reporting problems