CVE-2026-50593: Integer Underflow
Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/graphite2to a version that resolves this vulnerability.Fixed in 1.3.14-1+deb12u1Fixed in 1.3.14-2+deb13u1Fixed in 1.3.15-2 - Upgrade
Upgrade
Graphiteto a version that resolves this vulnerability.Fixed in 1.3.15
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50593?
The severity of CVE-2026-50593 is rated as high with a score of 7.3.
What type of vulnerability is CVE-2026-50593?
CVE-2026-50593 is classified as an integer underflow vulnerability.
How do I fix CVE-2026-50593?
To fix CVE-2026-50593, upgrade to Graphite version 1.3.15 or later.
What software is affected by CVE-2026-50593?
CVE-2026-50593 affects the SIL International Graphite software prior to version 1.3.15.
What are the potential impacts of CVE-2026-50593?
CVE-2026-50593 could result in out-of-bounds writes, leading to potential data corruption or unauthorized access.