CVE-2026-3282: libvips unpremultiply.c vips_unpremultiply_build out-of-bounds
A flaw has been found in libvips 8.19.0. This vulnerability affects the function vipsunpremultiplybuild of the file libvips/conversion/unpremultiply.c. Executing a manipulation of the argument alphaband can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been published and may be used. This patch is called 7215ead1e0cd7d3703cc4f5fca06d7d0f4c22b91. A patch should be applied to remediate this issue.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3282?
CVE-2026-3282 is classified as a moderate severity vulnerability due to potential out-of-bounds reads that could allow unauthorized access to sensitive information.
How do I fix CVE-2026-3282?
To remediate CVE-2026-3282, upgrade to the latest version of libvips that addresses this vulnerability.
Which versions of libvips are affected by CVE-2026-3282?
CVE-2026-3282 affects libvips version 8.19.0 and possibly earlier versions.
What impact does CVE-2026-3282 have on applications using libvips?
Applications using libvips are at risk of data leaks or unexpected behaviors due to the out-of-bounds read vulnerability described in CVE-2026-3282.
Is CVE-2026-3282 being actively exploited in the wild?
As of the latest information, there are no confirmed reports of CVE-2026-3282 being actively exploited in the wild.