CVE-2026-8212

A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWapi.c. Executing a manipulation can lead to heap-based buffer overflow. The attack requires local access. The exploit has been published and may be used. Upgrading to version 3.13.0RC1 addresses this issue. This patch is called 3e04c0385630e4d42517046d9a4967dfccfeb7fd. The affected component should be upgraded.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:gdal:3.13.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:gdal:3.13.0:beta2:*:*:*:*:*:*

History

19 May 2026, 20:01

Type Values Removed Values Added
References () https://github.com/OSGeo/gdal/ - () https://github.com/OSGeo/gdal/ - Product
References () https://github.com/OSGeo/gdal/commit/3e04c0385630e4d42517046d9a4967dfccfeb7fd - () https://github.com/OSGeo/gdal/commit/3e04c0385630e4d42517046d9a4967dfccfeb7fd - Patch
References () https://github.com/OSGeo/gdal/issues/14398 - () https://github.com/OSGeo/gdal/issues/14398 - Exploit, Issue Tracking, Mitigation, Patch
References () https://github.com/OSGeo/gdal/releases/tag/v3.13.0RC1 - () https://github.com/OSGeo/gdal/releases/tag/v3.13.0RC1 - Patch, Release Notes
References () https://github.com/biniamf/pocs/tree/main/gdal-swsdfldsrch_oob-read - () https://github.com/biniamf/pocs/tree/main/gdal-swsdfldsrch_oob-read - Exploit, Third Party Advisory
References () https://vuldb.com/submit/808127 - () https://vuldb.com/submit/808127 - Exploit, Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/362429 - () https://vuldb.com/vuln/362429 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/362429/cti - () https://vuldb.com/vuln/362429/cti - Permissions Required, VDB Entry
CPE cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:gdal:3.13.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:gdal:3.13.0:beta1:*:*:*:*:*:*
First Time Osgeo gdal
Osgeo
CWE CWE-125

09 May 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-09 23:16

Updated : 2026-05-19 20:01


NVD link : CVE-2026-8212

Mitre link : CVE-2026-8212

CVE.ORG link : CVE-2026-8212


JSON object : View

Products Affected

osgeo

  • gdal
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-122

Heap-based Buffer Overflow

CWE-125

Out-of-bounds Read