Impact
The SAIL image library contains a heap out‑of‑bounds write in its PSD decoder. When a one‑channel Bitmap PSD declares a depth of 8 bits the helper function resolves the image to one‑bit rows, yet the main decoder accepts the depth value and writes one byte per pixel. This mismatch allows maliciously crafted PSD files to corrupt the heap, reliably crash the application or, in worst cases, lead to arbitrary code execution.
Affected Systems
The flaw was found in HappySeaFox SAIL versions 0.9.10 and earlier. The update that corrects the depth handling, released as v1.0.0, is available in the GitHub repository. All code paths that load PSD files via sail_load_from_file() or sail_load_from_memory() are affected, regardless of platform, because SAIL is a cross‑platform library.
Risk and Exploitability
With a CVSS score of 9.8 the vulnerability is rated critical. The EPSS probability is reported as below 1 %, and the issue is not currently listed in CISA’s KEV catalog, but the high base score and the potential for code execution still warrant attention. The attack requires an application that uses SAIL to load a crafted PSD file, so an attacker could supply such a file to a vulnerable service or supply chain. Applying the v1.0.0 fix or otherwise preventing the decoder from processing malicious images mitigates the risk.
OpenCVE Enrichment