CVE-2026-3284
Severity CVSS v4.0:
MEDIUM
Type:
CWE-189
Numeric Errors
Publication date:
27/02/2026
Last modified:
27/02/2026
Description
A vulnerability was found in libvips 8.19.0. Impacted is the function vips_extract_area_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_area results in integer overflow. The attack requires a local approach. The exploit has been made public and could be used. The patch is identified as 24795bb3d19d84f7b6f5ed86451ad556c8f2fe70. It is advisable to implement a patch to correct this issue.
Impact
Base Score 4.0
4.80
Severity 4.0
MEDIUM
Base Score 3.x
3.30
Severity 3.x
LOW
Base Score 2.0
1.70
Severity 2.0
LOW
References to Advisories, Solutions, and Tools
- https://github.com/libvips/libvips/
- https://github.com/libvips/libvips/commit/24795bb3d19d84f7b6f5ed86451ad556c8f2fe70
- https://github.com/libvips/libvips/issues/4879
- https://github.com/libvips/libvips/issues/4879#issue-3944211794
- https://github.com/libvips/libvips/pull/4887
- https://vuldb.com/?ctiid_348013=
- https://vuldb.com/?id_348013=
- https://vuldb.com/?submit_758864=



