CVE-2026-3145 - Vulnerability Analysis
MediumCVSS: 5.3Last Updated: February 25, 2026
libvips - Memory Corruption
Published: February 25, 2026Updated: February 25, 2026PoC Available
Overview
libvips <= 8.18.0 contains a memory corruption vulnerability caused by improper handling in vips_foreign_load_matrix_file_is_a and vips_foreign_load_matrix_header functions, letting local attackers cause memory corruption, exploit requires local access.
Severity & Score
Severity: Medium
CVSS Score: 5.3
Impact
Local attackers can cause memory corruption, potentially leading to application crashes or code execution.
Mitigation
Apply the patch d4ce337c76bff1b278d7085c3c4f4725e3aa6ece or update to a version later than 8.18.0.
References
Related Resources
Details
- CVE ID
- CVE-2026-3145
- Severity
- Medium
- CVSS Score
- 5.3
- Type
- undefined
- Status
- confirmed
CWE
- CWE-119
CVSS Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L