Impact
The vulnerability resides in embedded-graphics's image_raw.rs, where the function ImageRaw::new/bytes_per_row can overflow the integer used for the number of bytes per row of an image. This overflow can corrupt memory, leading to denial of service or execution of arbitrary buffer operations. The weakness is a classic integer overflow (CWE‑189/CWE‑190). The software is commonly used in Rust projects that render graphics on embedded devices, so incorrect image handling may affect device firmware integrity.
Affected Systems
Embedded-graphics library versions up to 0.8.2 running on 32‑bit platforms are impacted. Projects that depend on this library without applying the later patch are vulnerable. No specific product names beyond the library itself are listed, but any application that imports embedded-graphics and renders images via ImageRaw::new is at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high severity. An EPSS score of < 1 % indicates a very low exploitation probability. The vulnerability is not listed in CISA KEV, so no active known exploitation is reported. The attack vector is remote, as the description explicitly states that the attack may be carried out remotely. An attacker can provide a crafted image that causes the bytes_per_row calculation to overflow, potentially leading to memory corruption and exploitation.
OpenCVE Enrichment