{"id":"CVE-2026-70653","summary":"libvips: Possible heap-based buffer read overflow when decoding a well-crafted RLE Radiance image","details":"libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-style Radiance RLE decoder in libvips/foreign/radiance.c can process a repeat marker at the beginning of a scanline in scanline_read_old and read q[-1] before any prior pixel exists. A crafted Radiance image loaded through VipsForeignLoadRad can therefore disclose four bytes of adjacent heap data, most likely other image data. This issue is fixed in version 8.18.3.","aliases":["GHSA-fh99-55jf-5hj3"],"modified":"2026-08-23T03:53:39.960687956Z","published":"2026-08-20T21:06:26.424Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70653.json"},"references":[{"type":"WEB","url":"https://github.com/libvips/libvips/releases/tag/v8.18.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70653.json"},{"type":"ADVISORY","url":"https://github.com/libvips/libvips/security/advisories/GHSA-fh99-55jf-5hj3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70653"},{"type":"FIX","url":"https://github.com/libvips/libvips/commit/dc945573e15d598054e701c65b90a35b16b19304"},{"type":"FIX","url":"https://github.com/libvips/libvips/pull/5037"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libvips/libvips","events":[{"introduced":"0"},{"fixed":"dc945573e15d598054e701c65b90a35b16b19304"},{"fixed":"3664cfc5dc2c5661288f5bf5a85ccc51c64c1626"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"8.18.3"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v8.18.3-rc1","v8.18.2","v8.18.1","v8.18.0","v8.18.0-rc3","v8.18.0-rc2","v8.18.0-rc1","v8.18.0-alpha2","v8.18.0-alpha1","v8.17.0-rc1","v8.17.0","v8.17.0-test4","v8.17.0-test3","v8.17.0-test2","v8.17.0-test1","v8.16.0","v8.16.0-rc2","v8.16.0-rc1","v8.15.0","v8.15.0-rc2","v8.14.0","v8.14.0-rc1","v8.13.0","v8.13.0-rc2","v8.13.0-rc1","v8.13.0-pre1","v8.12.0","v8.12.0-rc1","v8.11.0","v8.11","v8.11.0-rc1","v8.10.6-beta2","v8.10.0","v8.10.0-rc2","v8.10.0-rc1","v8.10.0-beta2","v8.10.0-beta1","v8.9.0","v8.9.0-rc4","v8.9.0-rc3","v8.9.0-rc2","v8.9.0-rc1","v8.9.0-beta2","v8.9.0-beta1","v8.9.0-alpha1","v8.8.0-rc3","v8.8.0","v8.8.0-rc2","v8.8.0-rc1","v8.7.0","v8.7.0-rc3","v8.7.0-rc2","v8.7.0-rc1","v8.7.0-alpha2","v8.6.0","v8.6.0-beta2","v8.6.0-beta1","v8.6.0-alpha2","v8.6.0-alpha1","v8.5.3","v8.5.2","v8.5.1","v8.3.0","v8.2.2","v8.1","v8.0-beta","v7.28.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70653.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}