CVE-2026-33019: libsixel: Integer overflow leads to Out-of-bounds Read in img2sixel
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow leading to an out-of-bounds heap read in the --crop option handling of img2sixel, where positive coordinates up to INTMAX are accepted without overflow-safe bounds checking. In sixelencoderdoclip(), the expression clipw + clipx overflows to a large negative value when clipx is INTMAX, causing the bounds guard to be skipped entirely, and the unclamped coordinate is passed through sixelframeclip() to clip(), which computes a source pointer far beyond the image buffer and passes it to memmove(). An attacker supplying a specially crafted crop argument with any valid image can trigger an out-of-bounds read in the heap, resulting in a reliable crash and potential information disclosure. This issue has been fixed in version 1.8.7-r1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libsixelto a version that resolves this vulnerability.Fixed in 1.8.7-r1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33019?
CVE-2026-33019 has a medium severity due to the potential for out-of-bounds reads that could be exploited.
How do I fix CVE-2026-33019?
To fix CVE-2026-33019, upgrade to libsixel version 1.8.8 or later.
What type of vulnerability is CVE-2026-33019?
CVE-2026-33019 is an integer overflow vulnerability that leads to out-of-bounds read.
Which versions of libsixel are affected by CVE-2026-33019?
Versions of libsixel up to and including 1.8.7 are affected by CVE-2026-33019.
What is the impact of CVE-2026-33019?
The impact of CVE-2026-33019 includes potential unauthorized memory access, leading to data leakage or crashes.