CVE-2026-3145: libvips matrixload.c vips_foreign_load_matrix_header memory corruption
A flaw has been found in libvips up to 8.18.0. The affected element is the function vipsforeignloadmatrixfileisa/vipsforeignloadmatrixheader of the file libvips/foreign/matrixload.c. Executing a manipulation can lead to memory corruption. The attack needs to be launched locally. This patch is called d4ce337c76bff1b278d7085c3c4f4725e3aa6ece. A patch should be applied to remediate this issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3145?
CVE-2026-3145 is classified as a memory corruption vulnerability in libvips that can lead to potential exploitation.
How do I fix CVE-2026-3145?
To fix CVE-2026-3145, update libvips to a version later than 8.18.0, where the vulnerability has been addressed.
Which versions of libvips are affected by CVE-2026-3145?
CVE-2026-3145 affects all versions of libvips up to and including 8.18.0.
What type of attack can exploit CVE-2026-3145?
CVE-2026-3145 can be exploited through crafted matrix files that are processed by the affected libvips functions.
Is CVE-2026-3145 a denial of service vulnerability?
CVE-2026-3145 may lead to unexpected behavior, including potential denial of service due to memory corruption.