CVE-2026-3147: libvips csvload.c vips_foreign_load_csv_build heap-based overflow
A vulnerability was found in libvips up to 8.18.0. This affects the function vipsforeignloadcsvbuild of the file libvips/foreign/csvload.c. The manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been made public and could be used. The patch is identified as b3ab458a25e0e261cbd1788474bbc763f7435780. It is advisable to implement a patch to correct this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3147?
CVE-2026-3147 has a high severity level due to its potential for a heap-based buffer overflow.
How do I fix CVE-2026-3147?
To fix CVE-2026-3147, upgrade libvips to a version newer than 8.18.0.
What type of vulnerability is CVE-2026-3147?
CVE-2026-3147 is a heap-based buffer overflow vulnerability.
What function is affected by CVE-2026-3147?
The function affected by CVE-2026-3147 is vips_foreign_load_csv_build in libvips.
Which versions of libvips are affected by CVE-2026-3147?
CVE-2026-3147 affects all versions of libvips up to and including 8.18.0.