Impact
SAIL is a cross‑platform image library whose TGA_INDEXED_RLE decoder erroneously calculates the pixel buffer size. In versions 0.9.10 and earlier, the decoder reserves a one‑byte per pixel buffer for indexed images but then writes each pixel using a size derived from an attacker‑controlled bpp value between 9 and 32. This leads to a heap out‑of‑bounds write. The flaw can corrupt heap structures, cause a crash, or enable arbitrary code execution.
Affected Systems
The affected product is the HappySeaFox Sail image library. All releases up to and including version 0.9.10 are vulnerable. The vulnerability was fixed in release 1.0.0, which can be downloaded from the GitHub releases page.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. EPSS is below 1 %, suggesting a low current exploitation probability, and the vulnerability is not listed in CISA KEV. However, since the flaw permits arbitrary code execution when an attacker supplies a crafted TGA file to sail_load_from_file or sail_load_from_memory, the effective risk to systems that process untrusted image data is significant. The likely attack vector is a local or remote execution of a malicious TGA image, exploiting the mismatch between the indexed‑RLE pixel size calculation and the actual pixel buffer.
OpenCVE Enrichment