{"id":"CVE-2026-54692","summary":"SAIL: XBM X10 decoder writes 2 bytes per literal into a 1-byte-per-literal buffer (heap out-of-bounds write)","details":"SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using the X11 one-byte-per-literal layout, but an X10 static short file causes the flat decode loop to write two file-controlled bytes per literal. When ceil(width/8) produces an odd row stride, the X10 literal count includes a padding byte for every row, but the destination has no space for those bytes, so loading the XBM through sail_load_from_file, sail_load_from_memory, or sail_start_loading_* produces a forward heap overwrite that scales with image height. The X11 static char path is not affected. The overwrite can corrupt process state, cause reliable crashes, and potentially enable code execution in a susceptible consuming application. This issue is fixed in version 1.0.0.","aliases":["GHSA-gp27-qv2x-55v5"],"modified":"2026-09-19T08:14:18.375856Z","published":"2026-09-17T19:47:57.832Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-131","CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54692.json"},"references":[{"type":"WEB","url":"https://github.com/HappySeaFox/sail/releases/tag/v1.0.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54692.json"},{"type":"ADVISORY","url":"https://github.com/HappySeaFox/sail/security/advisories/GHSA-gp27-qv2x-55v5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54692"},{"type":"FIX","url":"https://github.com/HappySeaFox/sail/commit/2991e18f806cf038038ee1ef9b08aa5d57480de1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/happyseafox/sail","events":[{"introduced":"0"},{"fixed":"2991e18f806cf038038ee1ef9b08aa5d57480de1"},{"fixed":"0f969168b9d19d43f448d2237990ec247ba822ca"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.0.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v0.9.10","v0.9.9","v0.9.8","v0.9.7","v0.9.6","v0.9.5","v0.9.4","v0.9.3","v0.9.2","v0.9.1","v0.9.0","v0.9.0-rc3","v0.9.0-rc2","v0.9.0-rc1","v0.9.0-pre23","v0.9.0-pre22","v0.9.0-pre21","v0.9.0-pre20","v0.9.0-pre19","v0.9.0-pre18","v0.9.0-pre17","v0.9.0-pre16","v0.9.0-pre15","v0.9.0-pre14","v0.9.0-pre13","v0.9.0-pre12","v0.9.0-pre11","v0.9.0-pre10","v0.9.0-pre9","v0.9.0-pre8","v0.9.0-pre7","v0.9.0-pre6","v0.9.0-pre5","v0.9.0-pre4","v0.9.0-pre3","v0.9.0-pre2","v0.9.0-pre1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54692.json","vanir_signatures_modified":"2026-09-19T08:14:18Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["142870923074762275860050379485050463354","27232702093219623301592544613884761292","192598216105551281128652527002278949981","282411544615747299361366255077201267063","309803770284331654039863278531256645174","8460411071204100105448837828724447343","67898633165191951248658226162095963645","183665860519023805065341116030955631704","88787575952005654932322319721346818106","33495523112487229563131776787350942536","35460774139294785059736759399025018419","97557666927950414872081160774411369037","68628455597863677729502949815846175568","300674678148950587232562686746984366557","232613061579722306234194099766831352856","47558462715601178620357662462871405513","199046724885295918924396745803483833754","145758652457648745994759328258847866826","30762637544571697143188952368406051027","37249849771689051094967118797184140857","12867863414534645829101232742643151018","274668795507872549031732830054114318779","247743520050546028330349100148791589032","320538354651029664436228357948097998631","68881060512949192524439042003300832909","329922038594316709470115622578854542870","62175700181784270307368950066808966709","89618716169129452448640761411765257402","314751509615733345822368381110393120903","74707313036691447071294777818533958583","199285846196972528544579415505693702032","69552956272979114868383034590409189701","13734423682608081695440871710404823591","127633043600479206354691303860731428129","335677415523018450397631034665653525518","126993864473997405147292419926440530711","29811608689211694209813390562236413268","49161693199811762003754640366261864871","16696434753029645814652117656418141529","11533884535776977557380656004382828167","196789560993891647638306753754654168734","14926057685805870804783381741710823107","62863038559075475030640736768828500217","63681457839739594380645379090727772883","255382463857575098110981392027987938603","43541056752652070748705150291644442915","181949068006295468756653684085113259038","122720800904880167872587031080330434477","2701420163366040822246483774494316059","135172835336769973082671830333438569867","159714259728966273004780490924466228668","327875259662622446770274704425355769973","61563442751682812674651417238845095180","80487732496549511112630764875175998680","248968943567416756681953152172132452353","132092135293909730813705577615303630588","17216959047668564756893152056971700615","143452874378341065756545730306074985413","190527522894240235057490312816473142788","79574478168365286437113237368472491416","316865666017252241651694862158394167909","114208416435151965271962920765135539020","47731934555469488930428262921105502420","26946359399744170047147096700596318259","6150475121917614077992156715472727105","219197611536585750697145589444343383270","103925663470932519838021159241786657096","339232633004316709808432178998027701682","209470740024369421756187092228283642582","40136740315495849646944703788682019344","207639055755229396473567562783927759871","33529010130793069097314528162137776311","49540440806544322250216433672974303133","197481812079012639668978228242876744369","187213152528244098568829006219182076575","216823703259877139377154694720004082571","151016847727202201556488788173598746374","162974290573380720163884033035860500269","266479966431750936683688465131475836717"],"threshold":0.9},"id":"CVE-2026-54692-1f83ca30","signature_type":"Line","signature_version":"v1","source":"https://github.com/happyseafox/sail/commit/2991e18f806cf038038ee1ef9b08aa5d57480de1","target":{"file":"src/sail-codecs/xbm/xbm.c"}},{"id":"CVE-2026-54692-4db66ff9","signature_type":"Function","signature_version":"v1","source":"https://github.com/happyseafox/sail/commit/2991e18f806cf038038ee1ef9b08aa5d57480de1","target":{"file":"src/sail-codecs/xbm/xbm.c","function":"sail_codec_load_frame_v8_xbm"},"deprecated":false,"digest":{"function_hash":"72457650393865267277283565998144466435","length":1826}},{"deprecated":false,"digest":{"function_hash":"333467786825962238802786177564052930590","length":1621},"id":"CVE-2026-54692-87f58a35","signature_type":"Function","signature_version":"v1","source":"https://github.com/happyseafox/sail/commit/2991e18f806cf038038ee1ef9b08aa5d57480de1","target":{"file":"src/sail-codecs/xbm/helpers.c","function":"xbm_private_write_pixels"}},{"signature_version":"v1","source":"https://github.com/happyseafox/sail/commit/2991e18f806cf038038ee1ef9b08aa5d57480de1","target":{"file":"src/sail-codecs/xbm/helpers.h"},"deprecated":false,"digest":{"line_hashes":["105885095165303057980772672517010859249","296720523125806227205272168246291834243","209810750558451220889996621586369199733"],"threshold":0.9},"id":"CVE-2026-54692-d89be9fd","signature_type":"Line"},{"source":"https://github.com/happyseafox/sail/commit/2991e18f806cf038038ee1ef9b08aa5d57480de1","target":{"file":"src/sail-codecs/xbm/helpers.c"},"deprecated":false,"digest":{"line_hashes":["127948599123846485441907754818647664958","66287450391812163424627546111513460936","184356494766544037566793818194032341098","178977017152877406776394624457540610311","231688758646126905771222127076541762877","57776845236414002788098110279680203737","297511623860050433399771338748346077368","75199487867602523489310977579782862434","204117064349340055338116552353621612312","122229248691878569632880685728376609657","29198592557107644961399903735240350298","128818753022681298376544503190616003715","52906030276475083063221016826941742322","259539171102390809101435755573743453036","274845437878209113331737773026956454057"],"threshold":0.9},"id":"CVE-2026-54692-ec6f6a6a","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}