Impact
The vulnerability originates from an integer overflow in the BMP loader of SerenityOS's LibGfx. When the height parameter of a BMP image is mal‑crafted, the multiplication used to calculate the required memory buffer overflows, leading to an incorrect large buffer size. This could result in memory corruption if the application allocates an undersized buffer or uses the corrupted size to read beyond buffer bounds. The description says the exploitation appears difficult and evidence for a practical exploit is thin, so no immediate remote code execution is confirmed. Nonetheless, the flaw exposes a potential for information disclosure or denial‑of‑service by corrupting memory.
Affected Systems
All SerenityOS builds prior to the patch commit 007041bb2dd6d140c9e707caddfb0a49ecf96469, including any rolling releases that have not yet applied the fix. The patch is applied in the latest SerenityOS master as of the supplied commit.
Risk and Exploitability
The CVSS score is 2.3, indicating low severity, and the EPSS score is not available, while the vulnerability is not listed in the CISA KEV catalog. The attack vector is possible remotely, with a high complexity and a difficult exploitation process. No publicly disclosed exploit is known, but the flaw can be leveraged to corrupt memory or cause denial‑of‑service if an attacker can supply specially crafted BMP files to a vulnerable system.
OpenCVE Enrichment