Impact
The vulnerability resides in the XBM X10 decoder of the HappySeaFox SAIL image library. The decoder allocates a one‑byte‑per‑literal buffer based on an X11 layout, but when processing an X10 static short file it writes two bytes for each literal. If the image width causes an odd row stride, an extra padding byte is included per row, exceeding the allocated buffer. This results in a forward heap overwrite that grows with image height. The out‑of‑bounds write can corrupt process memory, trigger crashes, and in applications that use SAIL, may be leveraged for arbitrary code execution. The flaw is a classic case of CWE‑131 (Incorrect Calculation of Buffer Size) and CWE‑787 (Out‑of‑Bounds Write).
Affected Systems
The affected component is the SAIL library distributed by HappySeaFox. All releases prior to v1.0.0, including the 0.9.x series found on GitHub, contain the buggy XBM X10 decoder. Applications that load XBM images through sail_load_from_file, sail_load_from_memory, or the streaming APIs are vulnerable if they rely on these pre‑1.0.0 versions.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8, indicating high severity. The EPSS score is below 1 %, suggesting a low yet non‑zero exploitation probability. It is not listed in CISA’s KEV catalog, so no known active exploits exist. The likely attack vector is remote image injection: an attacker supplies a crafted XBM X10 file to an application that uses SAIL, which then triggers the heap overwrite. If the consuming application is susceptible, the corruption may be leveraged for code execution. Defensive measures should focus on restricting untrusted image sources and applying the vendor patch.
OpenCVE Enrichment