{"id":"CVE-2026-8212","summary":"OSGeo gdal SWapi.c SWSDfldsrch heap-based overflow","details":"A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWapi.c. Executing a manipulation can lead to heap-based buffer overflow. The attack requires local access. The exploit has been published and may be used. Upgrading to version 3.13.0RC1 addresses this issue. This patch is called 3e04c0385630e4d42517046d9a4967dfccfeb7fd. The affected component should be upgraded.","aliases":["BIT-gdal-2026-8212","GHSA-r5m4-5vww-w9f5","PYSEC-2026-4"],"modified":"2026-08-12T16:09:24.613843Z","published":"2026-05-09T22:30:12.527Z","related":["CGA-m9x2-f4pv-vrfg"],"database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8212.json","unresolved_ranges":[{"extracted_events":[{"introduced":"3.13.0dev-4"},{"last_affected":"3.13.0dev-4"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://github.com/OSGeo/gdal/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8212.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8212"},{"type":"ADVISORY","url":"https://vuldb.com/submit/808127"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/362429"},{"type":"REPORT","url":"https://github.com/OSGeo/gdal/issues/14398"},{"type":"REPORT","url":"https://vuldb.com/vuln/362429/cti"},{"type":"FIX","url":"https://github.com/OSGeo/gdal/commit/3e04c0385630e4d42517046d9a4967dfccfeb7fd"},{"type":"FIX","url":"https://github.com/OSGeo/gdal/releases/tag/v3.13.0RC1"},{"type":"EVIDENCE","url":"https://github.com/biniamf/pocs/tree/main/gdal-swsdfldsrch_oob-read"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/osgeo/gdal","events":[{"introduced":"0"},{"last_affected":"0e3e27c90f57130232d215d783ff49cc332cd950"},{"introduced":"dd0742a208c40fc31293dd94f976d5ce4d01500f"},{"fixed":"3e04c0385630e4d42517046d9a4967dfccfeb7fd"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING","REFERENCES"],"cpe":["cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*:*","cpe:2.3:a:osgeo:gdal:3.13.0:beta1:*:*:*:*:*:*","cpe:2.3:a:osgeo:gdal:3.13.0:beta2:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"3.12.4"},{"introduced":"3.13.0-beta1"},{"last_affected":"3.13.0-beta1"},{"introduced":"3.13.0-beta2"},{"last_affected":"3.13.0-beta2"}]}}],"versions":["3.13.0-beta1","3.13.0-beta2","v3.12.4RC1","v3.12.4","v3.13.0beta1","v3.12.3RC2","v3.12.3","v3.12.3RC1","v3.12.2RC1","v3.12.2","v3.12.1RC1","v3.12.1","v3.12.0RC1","v3.12.0rc0","v3.12.0beta1","v3.12.0beta0","v3.11.0beta1","v3.8.0RC1","v3.8.0beta1","v3.6.0RC1","v3.5.0RC1","v3.3.0RC1","v3.3.0","v3.3.0beta1","v3.1.0RC1","3.0.3","2.4.4","v2.4.0","v2.3.0beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8212.json","vanir_signatures_modified":"2026-08-12T16:09:24Z","vanir_signatures":[{"digest":{"line_hashes":["167182038433977325088140875918359002134","326107720542469682361036124829195640199","145211092907363323265357074335233750441","191590602733504516798627237624263597385","65435948641469255597402762770679970626","251844773267004694610613087050398686949"],"threshold":0.9},"id":"CVE-2026-8212-364a1ce3","signature_type":"Line","signature_version":"v1","source":"https://github.com/osgeo/gdal/commit/3e04c0385630e4d42517046d9a4967dfccfeb7fd","target":{"file":"frmts/hdf4/hdf-eos/GDapi.c"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/osgeo/gdal/commit/3e04c0385630e4d42517046d9a4967dfccfeb7fd","target":{"file":"frmts/hdf4/hdf-eos/SWapi.c"},"deprecated":false,"digest":{"line_hashes":["47874982481244558623088493222637245073","33437425289549441688188381091884953329","248934914709926534082598085852344720376","191590602733504516798627237624263597385","65435948641469255597402762770679970626","251844773267004694610613087050398686949"],"threshold":0.9},"id":"CVE-2026-8212-49b53314"},{"source":"https://github.com/osgeo/gdal/commit/3e04c0385630e4d42517046d9a4967dfccfeb7fd","target":{"file":"frmts/hdf4/hdf-eos/SWapi.c","function":"SWSDfldsrch"},"deprecated":false,"digest":{"function_hash":"84405029591409210647790526936196376142","length":2208},"id":"CVE-2026-8212-98b5d44a","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"102204458867495531352866937965636611226","length":2255},"id":"CVE-2026-8212-d5bacd93","signature_type":"Function","signature_version":"v1","source":"https://github.com/osgeo/gdal/commit/3e04c0385630e4d42517046d9a4967dfccfeb7fd","target":{"file":"frmts/hdf4/hdf-eos/GDapi.c","function":"GDSDfldsrch"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}