Buffer over-read in libvips - CVE-2026-70652
Published: August 15, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information and cause a denial of service.
The vulnerability exists due to a buffer over-read in JPEG gain map encoding when resizing and re-encoding a JPEG with a gain map. A local user can process a specially crafted JPEG through a specific image pipeline to disclose sensitive information and cause a denial of service.
Only libvips instances compiled with support for libultrahdr are vulnerable.