CVE-2026-40492: SAIL has heap buffer overflow in XWD decoder — bits_per_pixel vs pixmap_depth type confusion in byte-swap

Published Apr 18, 2026
·
Updated

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02, the XWD codec resolves pixel format based on pixmapdepth but the byte-swap code uses bitsperpixel independently. When pixmapdepth=8 (BPP8INDEXED, 1 byte/pixel buffer) but bitsperpixel=32, the byte-swap loop accesses memory as uint32t, reading/writing 4x the allocated buffer size. This is a different vulnerability from the previously reported GHSA-3g38-x2pj-mv55 (CVE-2026-27168), which addressed bytesperline validation. Commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02 contains a patch.

Affected Software

1 affected component
SAIL SAIL<36aa5c7ec8a2bb35f6fb867a1177a6f141156b02

Event History

Apr 18, 2026
CVE Published
via MITRE·01:39 AM
Data Sourced
via MITRE·01:39 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-40492?

CVE-2026-40492 is a critical vulnerability due to a heap buffer overflow in the XWD decoder.

2

How do I fix CVE-2026-40492?

To fix CVE-2026-40492, you should update SAIL to a version including commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02 or later.

3

What vulnerability type is CVE-2026-40492 characterized as?

CVE-2026-40492 is characterized as a heap buffer overflow vulnerability.

4

What versions of SAIL are affected by CVE-2026-40492?

SAIL versions prior to commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02 are affected by CVE-2026-40492.

5

Is CVE-2026-40492 specific to any particular file format?

Yes, CVE-2026-40492 specifically affects the XWD codec in SAIL.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203