{"id":"CVE-2026-70652","summary":"libvips: Possible heap-based buffer read overflow when resizing and re-encoding a JPEG with gain map","details":"libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming JPEG to a very large output before encoding a gain map through VipsForeignSaveUhdr. The undersized allocation can cause a heap buffer over-read that may disclose adjacent data or crash the process. This issue is fixed in version 8.18.3.","aliases":["GHSA-h27h-jf9v-m8rg"],"modified":"2026-08-24T03:59:14.508616Z","published":"2026-08-20T21:04:51.898Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-126"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70652.json"},"references":[{"type":"WEB","url":"https://github.com/libvips/libvips/releases/tag/v8.18.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70652.json"},{"type":"ADVISORY","url":"https://github.com/libvips/libvips/security/advisories/GHSA-h27h-jf9v-m8rg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70652"},{"type":"FIX","url":"https://github.com/libvips/libvips/commit/cff17794f0698a4f47c74bb31c9700b2c83252a8"},{"type":"FIX","url":"https://github.com/libvips/libvips/pull/5039"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libvips/libvips","events":[{"introduced":"0"},{"fixed":"cff17794f0698a4f47c74bb31c9700b2c83252a8"},{"fixed":"3664cfc5dc2c5661288f5bf5a85ccc51c64c1626"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"8.18.3"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v8.18.3-rc1","v8.18.2","v8.18.1","v8.18.0","v8.18.0-rc3","v8.18.0-rc2","v8.18.0-rc1","v8.18.0-alpha2","v8.18.0-alpha1","v8.17.0-rc1","v8.17.0","v8.17.0-test4","v8.17.0-test3","v8.17.0-test2","v8.17.0-test1","v8.16.0","v8.16.0-rc2","v8.16.0-rc1","v8.15.0","v8.15.0-rc2","v8.14.0","v8.14.0-rc1","v8.13.0","v8.13.0-rc2","v8.13.0-rc1","v8.13.0-pre1","v8.12.0","v8.12.0-rc1","v8.11.0","v8.11","v8.11.0-rc1","v8.10.6-beta2","v8.10.0","v8.10.0-rc2","v8.10.0-rc1","v8.10.0-beta2","v8.10.0-beta1","v8.9.0","v8.9.0-rc4","v8.9.0-rc3","v8.9.0-rc2","v8.9.0-rc1","v8.9.0-beta2","v8.9.0-beta1","v8.9.0-alpha1","v8.8.0-rc3","v8.8.0","v8.8.0-rc2","v8.8.0-rc1","v8.7.0","v8.7.0-rc3","v8.7.0-rc2","v8.7.0-rc1","v8.7.0-alpha2","v8.6.0","v8.6.0-beta2","v8.6.0-beta1","v8.6.0-alpha2","v8.6.0-alpha1","v8.5.3","v8.5.2","v8.5.1","v8.3.0","v8.2.2","v8.1","v8.0-beta","v7.28.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70652.json","vanir_signatures_modified":"2026-08-24T03:59:14Z","vanir_signatures":[{"id":"CVE-2026-70652-4e5493d3","signature_type":"Line","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/3664cfc5dc2c5661288f5bf5a85ccc51c64c1626","target":{"file":"libvips/foreign/radiance.c"},"deprecated":false,"digest":{"line_hashes":["40871188566960555797534865343993917120","280583468346626059971461642282471659907","124457516850962973310175479744249140645","328053393552607056949457160698094811715","215634287215946805611721991023061710430","156768635521381228100771632092021262850","277582039530558050549102845751760158295","293496822736095924310907936123479200764","247399218563492718961184865847735965900","335249549507646226668533406698177255556","39003126028108026901725344741125630115","319954858964960260251026803592065571652","287170327211599960049231835358937974244","93930203671943223743569148747746365986"],"threshold":0.9}},{"deprecated":false,"digest":{"line_hashes":["328514610236387960317546307782831870221","111467087028955450532628775949531223436","160519221309831131626181757507565771342","65726386350385193732358062475643311346"],"threshold":0.9},"id":"CVE-2026-70652-5d75b059","signature_type":"Line","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/cff17794f0698a4f47c74bb31c9700b2c83252a8","target":{"file":"libvips/foreign/uhdrsave.c"}},{"deprecated":false,"digest":{"length":994,"function_hash":"72490777654407013462939268128658569853"},"id":"CVE-2026-70652-aed2a489","signature_type":"Function","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/3664cfc5dc2c5661288f5bf5a85ccc51c64c1626","target":{"file":"libvips/foreign/radiance.c","function":"scanline_read_old"}},{"id":"CVE-2026-70652-f680b4fb","signature_type":"Function","signature_version":"v1","source":"https://github.com/libvips/libvips/commit/cff17794f0698a4f47c74bb31c9700b2c83252a8","target":{"file":"libvips/foreign/uhdrsave.c","function":"vips_foreign_save_uhdr_set_raw_hdr"},"deprecated":false,"digest":{"function_hash":"29044277138172826812961938730596853197","length":880}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N"}]}