CVE-2026-3146

A vulnerability has been found in libvips up to 8.18.0. The impacted element is the function vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The identifier of the patch is d4ce337c76bff1b278d7085c3c4f4725e3aa6ece. To fix this issue, it is recommended to deploy a patch.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:libvips:libvips:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:43

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en libvips hasta la versión 8.18.0. El elemento afectado es la función vips_foreign_load_matrix_header del archivo libvips/foreign/matrixload.c. Si se manipula se provoca una desreferencia de puntero nulo. El ataque debe realizarse localmente. El identificador del parche es d4ce337c76bff1b278d7085c3c4f4725e3aa6ece. Para solucionar este problema, se recomienda desplegar el parche.

25 Feb 2026, 20:56

Type Values Removed Values Added
First Time Libvips libvips
Libvips
CPE cpe:2.3:a:libvips:libvips:*:*:*:*:*:*:*:*
References () https://github.com/libvips/libvips/ - () https://github.com/libvips/libvips/ - Product
References () https://github.com/libvips/libvips/commit/d4ce337c76bff1b278d7085c3c4f4725e3aa6ece - () https://github.com/libvips/libvips/commit/d4ce337c76bff1b278d7085c3c4f4725e3aa6ece - Patch
References () https://github.com/libvips/libvips/issues/4875 - () https://github.com/libvips/libvips/issues/4875 - Exploit, Issue Tracking, Vendor Advisory
References () https://github.com/libvips/libvips/pull/4888 - () https://github.com/libvips/libvips/pull/4888 - Issue Tracking, Patch
References () https://vuldb.com/?ctiid.347652 - () https://vuldb.com/?ctiid.347652 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.347652 - () https://vuldb.com/?id.347652 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.758691 - () https://vuldb.com/?submit.758691 - Third Party Advisory, VDB Entry

25 Feb 2026, 17:25

Type Values Removed Values Added
References () https://github.com/libvips/libvips/issues/4875 - () https://github.com/libvips/libvips/issues/4875 -

25 Feb 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-25 03:16

Updated : 2026-06-17 10:43


NVD link : CVE-2026-3146

Mitre link : CVE-2026-3146

CVE.ORG link : CVE-2026-3146


JSON object : View

Products Affected

libvips

  • libvips
CWE
CWE-404

Improper Resource Shutdown or Release

CWE-476

NULL Pointer Dereference