Impact
The flaw is an integer overflow caused by manipulating the width argument in the draw_sub_image function of the embedded-graphics Rust library. The overflow can corrupt internal calculations of buffer sizes or memory offsets, potentially leading to memory corruption, crashes, or, if the code runs with elevated privileges, to privilege escalation. The weakness is represented by CWE‑189 and CWE‑190.
Affected Systems
The embedded‑graphics Rust library, versions 0.8.0 through 0.8.2, are affected. This library is commonly used in embedded devices to render pixel data on displays. Any system that incorporates one of these versions and processes externally supplied images could be impacted.
Risk and Exploitability
The CVSS score is 6.9, indicating moderate severity. The EPSS score is less than 1%, implying a very low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote: an attacker can supply a crafted image to the application that uses the library and manipulate the width parameter to trigger the overflow.
OpenCVE Enrichment