Description
A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to integer overflow. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption
Action: Apply Patch
AI Analysis

Impact

The flaw is an integer overflow caused by manipulating the width argument in the draw_sub_image function of the embedded-graphics Rust library. The overflow can corrupt internal calculations of buffer sizes or memory offsets, potentially leading to memory corruption, crashes, or, if the code runs with elevated privileges, to privilege escalation. The weakness is represented by CWE‑189 and CWE‑190.

Affected Systems

The embedded‑graphics Rust library, versions 0.8.0 through 0.8.2, are affected. This library is commonly used in embedded devices to render pixel data on displays. Any system that incorporates one of these versions and processes externally supplied images could be impacted.

Risk and Exploitability

The CVSS score is 6.9, indicating moderate severity. The EPSS score is less than 1%, implying a very low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote: an attacker can supply a crafted image to the application that uses the library and manipulate the width parameter to trigger the overflow.

Generated by OpenCVE AI on September 15, 2026 at 17:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade embedded-graphics to a fixed version or apply the developer’s patch.
  • Validate image dimensions and reject requests where the width exceeds the actual image bounds.
  • Limit access to image rendering functions to trusted input or sandbox the rendering process.

Generated by OpenCVE AI on September 15, 2026 at 17:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to integer overflow. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
Title embedded-graphics image_raw.rs draw_sub_image integer overflow
First Time appeared Embedded-graphics
Embedded-graphics embedded-graphics
Weaknesses CWE-189
CWE-190
CPEs cpe:2.3:a:embedded-graphics:embedded-graphics:*:*:*:*:*:*:*:*
Vendors & Products Embedded-graphics
Embedded-graphics embedded-graphics
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Embedded-graphics Embedded-graphics
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T14:15:54.937Z

Reserved: 2026-09-12T18:18:43.570Z

Link: CVE-2026-90593

cve-icon Vulnrichment

Updated: 2026-09-16T14:15:51.243Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T21:17:02.787

Modified: 2026-09-16T15:18:32.180

Link: CVE-2026-90593

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T09:00:11Z

Weaknesses