CVE-2026-33328: Possible integer overflow on 32-bit systems when reading GIF images
libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the gifload operation could incorrectly determine dimensions leading to an integer overflow. This has been patched in version 8.18.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libvipsto a version that resolves this vulnerability.Fixed in 8.18.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33328?
CVE-2026-33328 has a risk rating of 37, indicating a significant security concern.
How do I fix CVE-2026-33328?
To fix CVE-2026-33328, update libvips to version 8.18.1 or later.
Which versions of libvips are affected by CVE-2026-33328?
CVE-2026-33328 affects libvips versions before and including 8.18.0.
What type of vulnerability is CVE-2026-33328?
CVE-2026-33328 is classified as an integer overflow vulnerability.
What impact could CVE-2026-33328 have on 32-bit systems?
On 32-bit systems, CVE-2026-33328 could lead to incorrect dimension determination when processing GIF images.