{"id":"BIT-gdal-2026-4738","summary":"GDAL Bundled zlib (inftree9.c) Pointer Offset Optimization Undefined Behavior Allows Heap Corruption or Remote Code Execution","details":"Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/contrib/infback9 modules). This vulnerability is associated with program files inftree9.C\u200e.\n\nThis issue affects gdal: before 3.11.0.","aliases":["CVE-2026-4738"],"modified":"2026-09-29T10:00:06.544773324Z","published":"2026-09-29T08:42:06.721Z","database_specific":{"severity":"Critical","cpes":["cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*:*"]},"references":[{"type":"WEB","url":"https://github.com/OSGeo/gdal/pull/12244"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4738"}],"affected":[{"package":{"name":"gdal","ecosystem":"Bitnami","purl":"pkg:bitnami/gdal"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.11.0"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/gdal/BIT-gdal-2026-4738.json"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:L/U:Amber"}]}],"schema_version":"1.9.0"}