CVE-2026-33328: Possible integer overflow on 32-bit systems when reading GIF images
Published Jul 20, 2026
·Updated
libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the gifload operation could incorrectly determine dimensions leading to an integer overflow. This has been patched in version 8.18.1.
Affected Software
2 affected components
libvips libvips<=8.18.0
libvips libvips<8.18.1
Remediation
Patch Available
Event History
Jul 20, 2026
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-33328?
CVE-2026-33328 has a risk rating of 37, indicating a significant security concern.
2
How do I fix CVE-2026-33328?
To fix CVE-2026-33328, update libvips to version 8.18.1 or later.
3
Which versions of libvips are affected by CVE-2026-33328?
CVE-2026-33328 affects libvips versions before and including 8.18.0.
4
What type of vulnerability is CVE-2026-33328?
CVE-2026-33328 is classified as an integer overflow vulnerability.
5
What impact could CVE-2026-33328 have on 32-bit systems?
On 32-bit systems, CVE-2026-33328 could lead to incorrect dimension determination when processing GIF images.