Description
A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be carried out remotely. Upgrading the affected component is recommended. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption / Potential Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in embedded-graphics's image_raw.rs, where the function ImageRaw::new/bytes_per_row can overflow the integer used for the number of bytes per row of an image. This overflow can corrupt memory, leading to denial of service or execution of arbitrary buffer operations. The weakness is a classic integer overflow (CWE‑189/CWE‑190). The software is commonly used in Rust projects that render graphics on embedded devices, so incorrect image handling may affect device firmware integrity.

Affected Systems

Embedded-graphics library versions up to 0.8.2 running on 32‑bit platforms are impacted. Projects that depend on this library without applying the later patch are vulnerable. No specific product names beyond the library itself are listed, but any application that imports embedded-graphics and renders images via ImageRaw::new is at risk.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate to high severity. An EPSS score of < 1 % indicates a very low exploitation probability. The vulnerability is not listed in CISA KEV, so no active known exploitation is reported. The attack vector is remote, as the description explicitly states that the attack may be carried out remotely. An attacker can provide a crafted image that causes the bytes_per_row calculation to overflow, potentially leading to memory corruption and exploitation.

Generated by OpenCVE AI on September 15, 2026 at 16:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade embedded-graphics to a version newer than 0.8.2
  • Ensure that any image data supplied to ImageRaw::new has bytes_per_row values within expected bounds before calling the function
  • If an upgrade is not immediately feasible, isolate the image processing component or apply defensive input validation to reject oversized images

Generated by OpenCVE AI on September 15, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be carried out remotely. Upgrading the affected component is recommended. The project was informed of the problem early through an issue report but has not responded yet.
Title embedded-graphics image_raw.rs new/bytes_per_row integer overflow
First Time appeared Embedded-graphics
Embedded-graphics embedded-graphics
Weaknesses CWE-189
CWE-190
CPEs cpe:2.3:a:embedded-graphics:embedded-graphics:*:*:*:*:*:*:*:*
Vendors & Products Embedded-graphics
Embedded-graphics embedded-graphics
References
Metrics cvssV2_0

{'score': 6.4, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Embedded-graphics Embedded-graphics
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T17:49:12.244Z

Reserved: 2026-09-12T18:34:50.396Z

Link: CVE-2026-90596

cve-icon Vulnrichment

Updated: 2026-09-15T17:48:12.975Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T22:17:00.577

Modified: 2026-09-15T18:19:37.327

Link: CVE-2026-90596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:30:11Z

Weaknesses