CVE-2026-33019

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow leading to an out-of-bounds heap read in the --crop option handling of img2sixel, where positive coordinates up to INT_MAX are accepted without overflow-safe bounds checking. In sixel_encoder_do_clip(), the expression clip_w + clip_x overflows to a large negative value when clip_x is INT_MAX, causing the bounds guard to be skipped entirely, and the unclamped coordinate is passed through sixel_frame_clip() to clip(), which computes a source pointer far beyond the image buffer and passes it to memmove(). An attacker supplying a specially crafted crop argument with any valid image can trigger an out-of-bounds read in the heap, resulting in a reliable crash and potential information disclosure. This issue has been fixed in version 1.8.7-r1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:saitoha:libsixel:*:*:*:*:*:*:*:*

History

25 Jul 2026, 10:10

Type Values Removed Values Added
Summary
  • (es) libsixel es una implementación de codificador/decodificador SIXEL derivada de sixel de kmiya. Las versiones 1.8.7 y anteriores contienen un desbordamiento de entero que conduce a una lectura fuera de límites en el heap en el manejo de la opción '--crop' de img2sixel, donde se aceptan coordenadas positivas hasta INT_MAX sin verificación de límites segura contra desbordamientos. En sixel_encoder_do_clip(), la expresión clip_w + clip_x desborda a un valor negativo grande cuando clip_x es INT_MAX, haciendo que la protección de límites se omita por completo, y la coordenada no restringida se pasa a través de sixel_frame_clip() a clip(), que calcula un puntero de origen mucho más allá del búfer de imagen y lo pasa a memmove(). Un atacante que proporciona un argumento de recorte ('crop') especialmente diseñado con cualquier imagen válida puede desencadenar una lectura fuera de límites en el heap, lo que resulta en un fallo ('crash') fiable y una potencial revelación de información. Este problema ha sido solucionado en la versión 1.8.7-r1.

23 Apr 2026, 14:47

Type Values Removed Values Added
First Time Saitoha
Saitoha libsixel
CPE cpe:2.3:a:saitoha:libsixel:*:*:*:*:*:*:*:*
References () https://github.com/saitoha/libsixel/releases/tag/v1.8.7-r1 - () https://github.com/saitoha/libsixel/releases/tag/v1.8.7-r1 - Release Notes
References () https://github.com/saitoha/libsixel/security/advisories/GHSA-c854-ffg9-g72c - () https://github.com/saitoha/libsixel/security/advisories/GHSA-c854-ffg9-g72c - Exploit, Vendor Advisory

15 Apr 2026, 20:16

Type Values Removed Values Added
References () https://github.com/saitoha/libsixel/security/advisories/GHSA-c854-ffg9-g72c - () https://github.com/saitoha/libsixel/security/advisories/GHSA-c854-ffg9-g72c -

14 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-14 22:16

Updated : 2026-07-25 10:10


NVD link : CVE-2026-33019

Mitre link : CVE-2026-33019

CVE.ORG link : CVE-2026-33019


JSON object : View

Products Affected

saitoha

  • libsixel
CWE
CWE-125

Out-of-bounds Read

CWE-190

Integer Overflow or Wraparound