Description
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using the X11 one-byte-per-literal layout, but an X10 static short file causes the flat decode loop to write two file-controlled bytes per literal. When ceil(width/8) produces an odd row stride, the X10 literal count includes a padding byte for every row, but the destination has no space for those bytes, so loading the XBM through sail_load_from_file, sail_load_from_memory, or sail_start_loading_* produces a forward heap overwrite that scales with image height. The X11 static char path is not affected. The overwrite can corrupt process state, cause reliable crashes, and potentially enable code execution in a susceptible consuming application. This issue is fixed in version 1.0.0.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Heap Out‑Of‑Bounds Write
Action: Update Library
AI Analysis

Impact

The vulnerability resides in the XBM X10 decoder of the HappySeaFox SAIL image library. The decoder allocates a one‑byte‑per‑literal buffer based on an X11 layout, but when processing an X10 static short file it writes two bytes for each literal. If the image width causes an odd row stride, an extra padding byte is included per row, exceeding the allocated buffer. This results in a forward heap overwrite that grows with image height. The out‑of‑bounds write can corrupt process memory, trigger crashes, and in applications that use SAIL, may be leveraged for arbitrary code execution. The flaw is a classic case of CWE‑131 (Incorrect Calculation of Buffer Size) and CWE‑787 (Out‑of‑Bounds Write).

Affected Systems

The affected component is the SAIL library distributed by HappySeaFox. All releases prior to v1.0.0, including the 0.9.x series found on GitHub, contain the buggy XBM X10 decoder. Applications that load XBM images through sail_load_from_file, sail_load_from_memory, or the streaming APIs are vulnerable if they rely on these pre‑1.0.0 versions.

Risk and Exploitability

The vulnerability has a CVSS score of 7.8, indicating high severity. The EPSS score is below 1 %, suggesting a low yet non‑zero exploitation probability. It is not listed in CISA’s KEV catalog, so no known active exploits exist. The likely attack vector is remote image injection: an attacker supplies a crafted XBM X10 file to an application that uses SAIL, which then triggers the heap overwrite. If the consuming application is susceptible, the corruption may be leveraged for code execution. Defensive measures should focus on restricting untrusted image sources and applying the vendor patch.

Generated by OpenCVE AI on September 19, 2026 at 03:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the SAIL library to version 1.0.0 or later, which corrects the buffer size calculation (CWE‑131) and removes the out‑of‑bounds write (CWE‑787).
  • If upgrading is not immediately possible, reject or refuse to load XBM X10 files from untrusted sources, or terminate the image loading process before the buffer is populated.
  • Incorporate bounds checking in the application so that each decoded pixel buffer matches the expected size for the image dimensions, thereby mitigating the out‑of‑bounds condition associated with both CWE‑131 and CWE‑787.

Generated by OpenCVE AI on September 19, 2026 at 03:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Happyseafox
Happyseafox sail
Vendors & Products Happyseafox
Happyseafox sail

Thu, 17 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using the X11 one-byte-per-literal layout, but an X10 static short file causes the flat decode loop to write two file-controlled bytes per literal. When ceil(width/8) produces an odd row stride, the X10 literal count includes a padding byte for every row, but the destination has no space for those bytes, so loading the XBM through sail_load_from_file, sail_load_from_memory, or sail_start_loading_* produces a forward heap overwrite that scales with image height. The X11 static char path is not affected. The overwrite can corrupt process state, cause reliable crashes, and potentially enable code execution in a susceptible consuming application. This issue is fixed in version 1.0.0.
Title SAIL: XBM X10 decoder writes 2 bytes per literal into a 1-byte-per-literal buffer (heap out-of-bounds write)
Weaknesses CWE-131
CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Happyseafox Sail
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T21:10:23.470Z

Reserved: 2026-06-15T22:58:06.562Z

Link: CVE-2026-54692

cve-icon Vulnrichment

Updated: 2026-09-21T21:10:17.230Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T20:16:52.550

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-54692

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:30:18Z

Weaknesses
  • CWE-131

    Incorrect Calculation of Buffer Size

  • CWE-787

    Out-of-bounds Write