Description
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-style Radiance RLE decoder in libvips/foreign/radiance.c can process a repeat marker at the beginning of a scanline in scanline_read_old and read q[-1] before any prior pixel exists. A crafted Radiance image loaded through VipsForeignLoadRad can therefore disclose four bytes of adjacent heap data, most likely other image data. This issue is fixed in version 8.18.3.
Published: 2026-08-20
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

A flaw in libvips’ old‑style Radiance RLE decoder allows the decoder to read one byte beyond the beginning of a scanline when the line starts with a repeat marker. The code accesses a heap location that holds four bytes of adjacent memory, which may contain image data or unrelated data. The read can leak these four bytes to the application, resulting in a modest disclosure of sensitive information stored on the heap at the time of decoding.

Affected Systems

The vulnerability exists in all libvips releases older than 8.18.3. Software that uses the foreign Radiance loader to import RLE‐encoded Radiance images is potentially exposed. The issue was fixed in libvips 8.18.3 and later releases.

Risk and Exploitability

The CVSS base score of 4.8 indicates a medium impact with limited severity. The EPSS score is less than 1 %, and the vulnerability is not listed in CISA’s KEV catalog, implying no confirmed exploitation. The likely attack vector is a local or remote application that processes a crafted Radiance file; by supplying such a file an attacker could obtain a few unintended bytes from memory. Overall, the risk is moderate, but the absence of active exploitation makes it a lower‑to‑moderate priority.

Generated by OpenCVE AI on September 10, 2026 at 05:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade libvips to version 8.18.3 or later.
  • If an upgrade cannot be performed immediately, disable Radiance RLE decoding or remove the foreign Radiance plugin to prevent processing of vulnerable images.
  • Ensure that any third‑party software that bundles libvips also receives the 8.18.3 update or later version.

Generated by OpenCVE AI on September 10, 2026 at 05:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

threat_severity

Low


Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Libvips
Libvips libvips
Vendors & Products Libvips
Libvips libvips

Thu, 20 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-style Radiance RLE decoder in libvips/foreign/radiance.c can process a repeat marker at the beginning of a scanline in scanline_read_old and read q[-1] before any prior pixel exists. A crafted Radiance image loaded through VipsForeignLoadRad can therefore disclose four bytes of adjacent heap data, most likely other image data. This issue is fixed in version 8.18.3.
Title libvips: Possible heap-based buffer read overflow when decoding a well-crafted RLE Radiance image
Weaknesses CWE-122
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-21T15:37:17.272Z

Reserved: 2026-08-04T21:48:08.612Z

Link: CVE-2026-70653

cve-icon Vulnrichment

Updated: 2026-08-21T15:37:11.722Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T21:17:08.427

Modified: 2026-09-18T20:09:01.757

Link: CVE-2026-70653

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-20T21:06:26Z

Links: CVE-2026-70653 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T05:45:06Z

Weaknesses