CVE-2026-70654
libvips: A well-crafted PPM image processed via a custom source could lead to possible heap buffer write overflow
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources and use them to process untrusted uncompressed PPM images can trigger a max/min error in vips_source_read_to_memory in libvips/iofuncs/source.c. The function uses VIPS_MAX instead of VIPS_MIN when selecting the remaining read size, allowing up to 4032 bytes to be written beyond the allocated heap buffer and causing memory corruption or a process crash. This issue is fixed in version 8.18.3.
| CWE | CWE-122 |
| Vendor | libvips |
| Product | libvips |
| Published | Aug 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for libvips libvips
Be the first to know when new unknown vulnerabilities affecting libvips libvips are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
libvips / libvips
< 8.18.3
References
github.com: https://github.com/libvips/libvips/security/advisories/GHSA-rjmm-3qch-m9rg github.com: https://github.com/libvips/libvips/pull/5038 github.com: https://github.com/libvips/libvips/commit/80e021c6cdda0f80b756c2109d99839c94c03258 github.com: https://github.com/libvips/libvips/releases/tag/v8.18.3