CVE-2026-3146: libvips matrixload.c vips_foreign_load_matrix_header null pointer dereference
A vulnerability has been found in libvips up to 8.18.0. The impacted element is the function vipsforeignloadmatrixheader of the file libvips/foreign/matrixload.c. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The identifier of the patch is d4ce337c76bff1b278d7085c3c4f4725e3aa6ece. To fix this issue, it is recommended to deploy a patch.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3146?
The severity of CVE-2026-3146 is considered to be moderate due to the potential for a null pointer dereference issue.
How do I fix CVE-2026-3146?
To fix CVE-2026-3146, upgrade libvips to a version higher than 8.18.0, where the vulnerability is addressed.
What systems are affected by CVE-2026-3146?
CVE-2026-3146 affects versions of libvips up to and including 8.18.0 on systems that utilize this library.
Can CVE-2026-3146 be exploited remotely?
CVE-2026-3146 is typically not considered a remote exploit as it requires specific conditions to trigger the null pointer dereference.
What are the potential impacts of CVE-2026-3146?
The potential impacts of CVE-2026-3146 include application crashes and possible denial of service due to the null pointer dereference.