{"id":"JLSEC-2026-766","summary":"GDAL: scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow","details":"In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in `frmts/netcdf/netcdfsg.cpp`.","modified":"2026-07-25T18:24:52.936828167Z","published":"2026-07-15T21:25:44.755Z","upstream":["CVE-2026-49014","GHSA-wphc-7cm7-8mf7","EUVD-2026-32039","PYSEC-2026-193"],"database_specific":{"license":"CC-BY-4.0","sources":[{"database_specific":{"status":"Analyzed"},"id":"CVE-2026-49014","imported":"2026-07-17T22:38:26.624Z","modified":"2026-06-17T10:55:27.107Z","published":"2026-05-27T02:16:34.180Z","url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-49014","html_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49014"},{"imported":"2026-07-17T22:38:26.782Z","modified":"2026-07-01T18:07:08Z","published":"2026-05-27T03:30:31Z","url":"https://api.github.com/advisories/GHSA-wphc-7cm7-8mf7","html_url":"https://github.com/advisories/GHSA-wphc-7cm7-8mf7","id":"GHSA-wphc-7cm7-8mf7"},{"imported":"2026-07-17T22:38:35.566Z","modified":"2026-05-27T13:52:05Z","published":"2026-05-27T01:39:18Z","url":"https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-32039","html_url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-32039","id":"EUVD-2026-32039"}]},"references":[{"type":"WEB","url":"https://github.com/OSGeo/gdal/blob/v3.13.1/NEWS.md"},{"type":"WEB","url":"https://github.com/OSGeo/gdal/commit/f5ebabc1042f3c59b24e7c8ad45dda242d127f09"},{"type":"WEB","url":"https://github.com/OSGeo/gdal/issues/14594"},{"type":"WEB","url":"https://github.com/OSGeo/gdal/pull/14598"},{"type":"WEB","url":"https://github.com/advisories/GHSA-wphc-7cm7-8mf7"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/gdal/PYSEC-2026-193.yaml"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49014"}],"affected":[{"package":{"name":"GDAL_jll","ecosystem":"Julia","purl":"pkg:julia/GDAL_jll?uuid=a7073274-a066-55f0-b90d-d619367d196c"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.2.0+0"},{"fixed":"305.1300.100+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-766.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}