CVE-2026-33327: Possible integer overflow leading to potential heap-based buffer overflow
libvips is a fast image processing library with low memory needs. The vipsload operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in version 8.18.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libvips (vipsload)to a version that resolves this vulnerability.Fixed in 8.18.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33327?
The severity of CVE-2026-33327 is rated at 60.
How do I fix CVE-2026-33327?
To fix CVE-2026-33327, upgrade to libvips version 8.18.1 or later.
What types of vulnerabilities are associated with CVE-2026-33327?
CVE-2026-33327 involves an integer overflow leading to a heap-based buffer overflow.
Which operation in libvips is affected by CVE-2026-33327?
The affected operation in libvips is the `vipsload` operation.
What versions of libvips are impacted by CVE-2026-33327?
Libvips versions before and including 8.18.0 are impacted by CVE-2026-33327.