Description
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap color mode to SAIL_PIXEL_FORMAT_BPP1_INDEXED without requiring the file depth to be one, so the pixel buffer uses one-bit rows while sail_codec_load_frame_v8_psd() in src/sail-codecs/psd/psd.c accepts depth == 8 and writes one attacker-controlled byte per pixel. Loading a crafted PSD through sail_load_from_file() or sail_load_from_memory() therefore writes beyond each heap row, causing memory corruption, a reliable crash, or potential code execution. This mode/depth mismatch is distinct from GHSA-rcqx-gc76-r9mv and GHSA-wcj8-hxxf-pq2c. This issue is fixed in version 1.0.0.
Published: 2026-09-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The SAIL image library contains a heap out‑of‑bounds write in its PSD decoder. When a one‑channel Bitmap PSD declares a depth of 8 bits the helper function resolves the image to one‑bit rows, yet the main decoder accepts the depth value and writes one byte per pixel. This mismatch allows maliciously crafted PSD files to corrupt the heap, reliably crash the application or, in worst cases, lead to arbitrary code execution.

Affected Systems

The flaw was found in HappySeaFox SAIL versions 0.9.10 and earlier. The update that corrects the depth handling, released as v1.0.0, is available in the GitHub repository. All code paths that load PSD files via sail_load_from_file() or sail_load_from_memory() are affected, regardless of platform, because SAIL is a cross‑platform library.

Risk and Exploitability

With a CVSS score of 9.8 the vulnerability is rated critical. The EPSS probability is reported as below 1 %, and the issue is not currently listed in CISA’s KEV catalog, but the high base score and the potential for code execution still warrant attention. The attack requires an application that uses SAIL to load a crafted PSD file, so an attacker could supply such a file to a vulnerable service or supply chain. Applying the v1.0.0 fix or otherwise preventing the decoder from processing malicious images mitigates the risk.

Generated by OpenCVE AI on September 19, 2026 at 01:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to SAIL v1.0.0 or newer, which corrects the depth handling and removes the out‑of‑bounds write.
  • If an upgrade is not immediately possible, validate PSD input before decoding: reject Bitmap mode files that declare a depth of 8 bits, or sandbox the decoding operation in a hardened process that has ASLR, stack canaries and memory‑protection enabled.
  • Monitor for abnormal crashes or memory corruption in applications that use SAIL, and deploy runtime defenses such as Address Space Layout Randomization and executable‑memory protection to reduce the impact of any remaining vulnerabilities.

Generated by OpenCVE AI on September 19, 2026 at 01:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Happyseafox
Happyseafox sail
Vendors & Products Happyseafox
Happyseafox sail

Thu, 17 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap color mode to SAIL_PIXEL_FORMAT_BPP1_INDEXED without requiring the file depth to be one, so the pixel buffer uses one-bit rows while sail_codec_load_frame_v8_psd() in src/sail-codecs/psd/psd.c accepts depth == 8 and writes one attacker-controlled byte per pixel. Loading a crafted PSD through sail_load_from_file() or sail_load_from_memory() therefore writes beyond each heap row, causing memory corruption, a reliable crash, or potential code execution. This mode/depth mismatch is distinct from GHSA-rcqx-gc76-r9mv and GHSA-wcj8-hxxf-pq2c. This issue is fixed in version 1.0.0.
Title SAIL: Heap out-of-bounds write in SAIL PSD decoder (Bitmap mode ignores depth)
Weaknesses CWE-122
CWE-787
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Happyseafox Sail
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T20:10:15.233Z

Reserved: 2026-06-15T20:07:02.185Z

Link: CVE-2026-54627

cve-icon Vulnrichment

Updated: 2026-09-18T20:10:10.981Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T20:16:52.117

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-54627

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T01:45:16Z

Weaknesses