Out-of-bounds write in MapServer - #VU146014

 

Out-of-bounds write in MapServer - #VU146014

Published: August 27, 2026


Vulnerability identifier: #VU146014
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds write in msInterpolationDataset() in src/interpolation.c when handling an unauthenticated WMS GetMap request for published interpolation layers with crafted WIDTH and HEIGHT values. A remote attacker can send a specially crafted GetMap request to cause a denial of service.

Only instances that publish interpolation layers using CONNECTIONTYPE IDW or CONNECTIONTYPE KERNELDENSITY are vulnerable.


Affected software

MapServer

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins