{"id":"CVE-2026-8084","summary":"OSGeo gdal HDF-EOS Grid File SWapi.c memmove out-of-bounds","details":"A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hdf-eos/SWapi.c of the component HDF-EOS Grid File Handler. This manipulation causes out-of-bounds read. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.13.0RC1 is able to resolve this issue. Patch name: a791f70f8eaec540974ec989ca6fb00266b7646c. Upgrading the affected component is advised.","aliases":["BIT-gdal-2026-8084","PYSEC-2026-2153"],"modified":"2026-08-12T16:09:22.136802Z","published":"2026-05-07T18:30:13.275Z","database_specific":{"cwe_ids":["CWE-119","CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8084.json","unresolved_ranges":[{"extracted_events":[{"introduced":"3.13.0dev-4"},{"last_affected":"3.13.0dev-4"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"VulDB"},"references":[{"type":"WEB","url":"https://github.com/OSGeo/gdal/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8084.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8084"},{"type":"ADVISORY","url":"https://vuldb.com/submit/808034"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/361838"},{"type":"REPORT","url":"https://github.com/OSGeo/gdal/issues/14378"},{"type":"REPORT","url":"https://vuldb.com/vuln/361838/cti"},{"type":"FIX","url":"https://github.com/OSGeo/gdal/commit/a791f70f8eaec540974ec989ca6fb00266b7646c"},{"type":"FIX","url":"https://github.com/OSGeo/gdal/releases/tag/v3.13.0RC1"},{"type":"EVIDENCE","url":"https://github.com/biniamf/pocs/blob/main/gdal_swfinfo_dimlist_oob-rw"},{"type":"EVIDENCE","url":"https://github.com/biniamf/pocs/tree/main/gdal_swfinfo_dimlist_oob-rw"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/osgeo/gdal","events":[{"introduced":"0"},{"last_affected":"0e3e27c90f57130232d215d783ff49cc332cd950"},{"introduced":"dd0742a208c40fc31293dd94f976d5ce4d01500f"},{"fixed":"a791f70f8eaec540974ec989ca6fb00266b7646c"}],"database_specific":{"cpe":["cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*:*","cpe:2.3:a:osgeo:gdal:3.13.0:beta1:*:*:*:*:*:*","cpe:2.3:a:osgeo:gdal:3.13.0:beta2:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"3.12.4"},{"introduced":"3.13.0-beta1"},{"last_affected":"3.13.0-beta1"},{"introduced":"3.13.0-beta2"},{"last_affected":"3.13.0-beta2"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["3.13.0-beta1","3.13.0-beta2","v3.12.4RC1","v3.12.4","v3.13.0beta1","v3.12.3RC2","v3.12.3","v3.12.3RC1","v3.12.2RC1","v3.12.2","v3.12.1RC1","v3.12.1","v3.12.0RC1","v3.12.0rc0","v3.12.0beta1","v3.12.0beta0","v3.11.0beta1","v3.8.0RC1","v3.8.0beta1","v3.6.0RC1","v3.5.0RC1","v3.3.0RC1","v3.3.0","v3.3.0beta1","v3.1.0RC1","3.0.3","2.4.4","v2.4.0","v2.3.0beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8084.json","vanir_signatures_modified":"2026-08-12T16:09:22Z","vanir_signatures":[{"target":{"file":"frmts/hdf4/hdf-eos/GDapi.c","function":"GDfieldinfo"},"deprecated":false,"digest":{"function_hash":"285311337474165479603245677509293117146","length":2619},"id":"CVE-2026-8084-1d97f454","signature_type":"Function","signature_version":"v1","source":"https://github.com/osgeo/gdal/commit/a791f70f8eaec540974ec989ca6fb00266b7646c"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/osgeo/gdal/commit/a791f70f8eaec540974ec989ca6fb00266b7646c","target":{"file":"frmts/hdf4/hdf-eos/SWapi.c","function":"SWfinfo"},"deprecated":false,"digest":{"function_hash":"296266930662382277819761698497124010906","length":3042},"id":"CVE-2026-8084-d28ee072"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/osgeo/gdal/commit/a791f70f8eaec540974ec989ca6fb00266b7646c","target":{"file":"frmts/hdf4/hdf-eos/GDapi.c"},"deprecated":false,"digest":{"line_hashes":["290815317125878387779841054426990916384","60171234605230396493797647493825640149","277904157858091376862875188962579496126","7261014713952251831243630176363429660","34826176973746473582423610340012125795"],"threshold":0.9},"id":"CVE-2026-8084-d3cc47c7"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/osgeo/gdal/commit/a791f70f8eaec540974ec989ca6fb00266b7646c","target":{"file":"frmts/hdf4/hdf-eos/SWapi.c"},"deprecated":false,"digest":{"line_hashes":["290815317125878387779841054426990916384","60171234605230396493797647493825640149","277904157858091376862875188962579496126","7261014713952251831243630176363429660","34826176973746473582423610340012125795"],"threshold":0.9},"id":"CVE-2026-8084-f96a7cfe"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}