CVE-2026-3281

high

Description

A vulnerability was detected in libvips 8.19.0. This affects the function vips_bandrank_build of the file libvips/conversion/bandrank.c. Performing a manipulation of the argument index results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit is now public and may be used. The patch is named fd28c5463697712cb0ab116a2c55e4f4d92c4088. It is suggested to install a patch to address this issue.

References

https://vuldb.com/?submit.758861

https://vuldb.com/?id.348010

https://vuldb.com/?ctiid.348010

https://github.com/libvips/libvips/pull/4895

https://github.com/libvips/libvips/issues/4878#issue-3944209102

https://github.com/libvips/libvips/issues/4878

https://github.com/libvips/libvips/commit/fd28c5463697712cb0ab116a2c55e4f4d92c4088

https://github.com/libvips/libvips/

Details

Source: Mitre, NVD

Published: 2026-02-27

Updated: 2026-02-27

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 8.4

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High