{"id":"CVE-2026-70651","summary":"libvips: Possible integer overflow when reading multi-page TIFF images via ImageMagick","details":"libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height while loading a crafted multi-page TIFF through VipsForeignLoadMagick. The vulnerable calculations in libvips/foreign/magick6load.c and libvips/foreign/magick7load.c multiply the per-page Ysize by n_frames without a checked bound, which can cause a heap buffer over-read and process crash. Most package-manager builds include libtiff and do not use this affected fallback path. This issue is fixed in version 8.18.3.","aliases":["GHSA-7p29-wg2h-36q4"],"modified":"2026-09-20T14:13:54.764978Z","published":"2026-08-20T21:05:38.765Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-680"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70651.json"},"references":[{"type":"WEB","url":"https://github.com/libvips/libvips/releases/tag/v8.18.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70651.json"},{"type":"ADVISORY","url":"https://github.com/libvips/libvips/security/advisories/GHSA-7p29-wg2h-36q4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70651"},{"type":"FIX","url":"https://github.com/libvips/libvips/commit/05719ca3d5852acdeb6714de2e8e769c9a5d2c11"},{"type":"FIX","url":"https://github.com/libvips/libvips/pull/5040"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libvips/libvips","events":[{"introduced":"0"},{"fixed":"05719ca3d5852acdeb6714de2e8e769c9a5d2c11"},{"fixed":"3664cfc5dc2c5661288f5bf5a85ccc51c64c1626"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"8.18.3"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v8.18.3-rc1","v8.18.2","v8.18.1","v8.18.0","v8.18.0-rc3","v8.18.0-rc2","v8.18.0-rc1","v8.18.0-alpha2","v8.18.0-alpha1","v8.17.0-rc1","v8.17.0","v8.17.0-test4","v8.17.0-test3","v8.17.0-test2","v8.17.0-test1","v8.16.0","v8.16.0-rc2","v8.16.0-rc1","v8.15.0","v8.15.0-rc2","v8.14.0","v8.14.0-rc1","v8.13.0","v8.13.0-rc2","v8.13.0-rc1","v8.13.0-pre1","v8.12.0","v8.12.0-rc1","v8.11.0","v8.11","v8.11.0-rc1","v8.10.6-beta2","v8.10.0","v8.10.0-rc2","v8.10.0-rc1","v8.10.0-beta2","v8.10.0-beta1","v8.9.0","v8.9.0-rc4","v8.9.0-rc3","v8.9.0-rc2","v8.9.0-rc1","v8.9.0-beta2","v8.9.0-beta1","v8.9.0-alpha1","v8.8.0-rc3","v8.8.0","v8.8.0-rc2","v8.8.0-rc1","v8.7.0","v8.7.0-rc3","v8.7.0-rc2","v8.7.0-rc1","v8.7.0-alpha2","v8.6.0","v8.6.0-beta2","v8.6.0-beta1","v8.6.0-alpha2","v8.6.0-alpha1","v8.5.3","v8.5.2","v8.5.1","v8.3.0","v8.2.2","v8.1","v8.0-beta","v7.28.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70651.json","vanir_signatures_modified":"2026-09-20T14:13:54Z","vanir_signatures":[{"id":"CVE-2026-70651-19fa97fd","signature_type":"Function","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/05719ca3d5852acdeb6714de2e8e769c9a5d2c11","target":{"file":"libvips/foreign/magick7load.c","function":"vips_foreign_load_magick7_parse"},"deprecated":false,"digest":{"function_hash":"133100259407859406808124327052401871797","length":4413}},{"id":"CVE-2026-70651-248910ef","signature_type":"Function","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/05719ca3d5852acdeb6714de2e8e769c9a5d2c11","target":{"file":"libvips/foreign/magick6load.c","function":"vips_foreign_load_magick_parse"},"deprecated":false,"digest":{"function_hash":"273117496005949803302300327155569486394","length":5463}},{"deprecated":false,"digest":{"function_hash":"23454626213952632203291191550593093301","length":644},"id":"CVE-2026-70651-3521dd8a","signature_type":"Function","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/05719ca3d5852acdeb6714de2e8e769c9a5d2c11","target":{"file":"libvips/foreign/magick6load.c","function":"vips_foreign_load_magick_load"}},{"digest":{"line_hashes":["40871188566960555797534865343993917120","280583468346626059971461642282471659907","124457516850962973310175479744249140645","328053393552607056949457160698094811715","215634287215946805611721991023061710430","156768635521381228100771632092021262850","277582039530558050549102845751760158295","293496822736095924310907936123479200764","247399218563492718961184865847735965900","335249549507646226668533406698177255556","39003126028108026901725344741125630115","319954858964960260251026803592065571652","287170327211599960049231835358937974244","93930203671943223743569148747746365986"],"threshold":0.9},"id":"CVE-2026-70651-4e5493d3","signature_type":"Line","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/3664cfc5dc2c5661288f5bf5a85ccc51c64c1626","target":{"file":"libvips/foreign/radiance.c"},"deprecated":false},{"source":"https://github.com/libvips/libvips/commit/05719ca3d5852acdeb6714de2e8e769c9a5d2c11","target":{"file":"libvips/foreign/magick6load.c"},"deprecated":false,"digest":{"line_hashes":["147859986739528962911087853982830540776","137100777859514078515719273119741841869","218746259535429919254732594036671378","126533994257590355404829968574946985610","75148570068093254686216119935600497341","61708108129258068648898165005992319753","46853057962266642126344685130104221441","242276331998192232705958853413378247793","27064207974371886793024833326979516446","114246597397452084616935532596703140519","86101220347965472869584548285946540965","94302005186203886659063702658651658071","109097698511346898400229593806513668496","238145477544407870873219109922130099869","245488359390796695623351127047720243191","167444532627288115539448057976104684622","170334155107580861385954872227100837512","173953713461423367295728450953680860037","157328736971389778826598568569141442591","239515608749242570787590060678517811046","115949694970394558452143470987831984681","19545224077617991218608147817342547787","313243214823534861794243762095372227793","1597175282200692683205151808849092244","161326644718737322615498321321406532101","297552713231836338625666822528634710960","255498575676639679647745702188299413633","28599128002719611189700939848029555339","295328085800850397119752390926599004134","161323421198237360796698328486932046755","316425793631918567365361934404028639685","258655174097726186293417794383923668005","206659081282882101920430509186621436208","66695922072754388120231195657327376705","304572514280791209636789273855178537326","339379154025212429263379761646351861563","46664902951711110944677107610456833111","67031757405684072656392830332652328836","41406121026771511394854032457206754847","178119808070977222438246581396606213510","325542137031850258593103476961917275594","51549371474112037101420425463229213086","117982089047312686485184123600983022695","45458151713064963726911809033057562430","321765118425877242917683263780815768029","139857263241934054720293865558637007067","138745910462533522894562434753580441574","62521846656345307631008697597642305765","303364960374776536979901988489239067948","258363134389440094892601912465173457232","194389836606109891768463411438783053278","246734488423500602089886404683743396413","324495642094621132663570326266424791640","287211923446630299713695641040904176542"],"threshold":0.9},"id":"CVE-2026-70651-6eb76ada","signature_type":"Line","signature_version":"v1"},{"id":"CVE-2026-70651-708dc3d5","signature_type":"Function","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/05719ca3d5852acdeb6714de2e8e769c9a5d2c11","target":{"file":"libvips/foreign/magick7load.c","function":"vips_foreign_load_magick7_load"},"deprecated":false,"digest":{"function_hash":"49215442232878843798805567670099318028","length":1042}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/05719ca3d5852acdeb6714de2e8e769c9a5d2c11","target":{"file":"libvips/foreign/magick7load.c"},"deprecated":false,"digest":{"line_hashes":["212570681316336255770076739274438297052","108163302262556142356321947819979265540","68983918234948119477763896033483107366","37391680511791587663715428090377834605","24397149483294534750331088458909044946","141418903450025934770564139572218648524","24121580158856095063480326912414589224","331941237030385597668966363301847891964","61206138210212822245937007870280113825","122039411137913252494318865715476644940","61708108129258068648898165005992319753","46853057962266642126344685130104221441","281285403625060261254269175116966356609","66073976175944195606768717805639173620","70849278559514177989209100264704511312","116351803909491058643250500819440418991","89669145524071909635888754479831760715","229679191716454478189654366516363069461","300292859584881361465566024137793887764","152993862630079281347106750786847796090","172575079020220334798765135290578404895","277014105797888662830062963927710567418","7298154163967254332568441801390568104","320778469665342587903355952555699426789","2918989490978440326883496803535368422","84012572158142202087096791696324585399","45574597214460442209536682510697802996","291077816821614888026848001184056764452","206885010598215765378216069175940867663","336678019395890272551088252184663083281","157087308715841900012155023430490374453","161313182845185547984854796174473124921","232430163607419274964902731954896088922","340004709655305497314398690867928067428","108051171526297466954776722326447940533","127200643574089900406745808102095710595","214425003083561583649843334292981415113","44481450882355838763881949611083434196","180737930047612712374356315089860354830","200411644053308944915437582899204468715","87838118461025449157492792870220006171","170587666540786228192703654031645941917","124266777520513392011033810066819665536","171532961243319949319777162554903682898","179779657998060333402008743229113752536"],"threshold":0.9},"id":"CVE-2026-70651-86e3520a"},{"target":{"file":"libvips/foreign/radiance.c","function":"scanline_read_old"},"deprecated":false,"digest":{"length":994,"function_hash":"72490777654407013462939268128658569853"},"id":"CVE-2026-70651-aed2a489","signature_type":"Function","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/3664cfc5dc2c5661288f5bf5a85ccc51c64c1626"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"}]}