CVE-2026-8213

A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4/hdf-eos/GDapi.c of the component Grid File Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 3.13.0RC1 can resolve this issue. The identifier of the patch is 3e04c0385630e4d42517046d9a4967dfccfeb7fd. It is suggested to upgrade the affected component.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:gdal:3.13.0:beta1:*:*:*:*:*:*
cpe:2.3:a:osgeo:gdal:3.13.0:beta2:*:*:*:*:*:*

History

19 May 2026, 19:58

Type Values Removed Values Added
References () https://github.com/OSGeo/gdal/ - () https://github.com/OSGeo/gdal/ - Product
References () https://github.com/OSGeo/gdal/commit/3e04c0385630e4d42517046d9a4967dfccfeb7fd - () https://github.com/OSGeo/gdal/commit/3e04c0385630e4d42517046d9a4967dfccfeb7fd - Patch
References () https://github.com/OSGeo/gdal/issues/14399 - () https://github.com/OSGeo/gdal/issues/14399 - Issue Tracking, Mitigation, Exploit, Patch
References () https://github.com/OSGeo/gdal/releases/tag/v3.13.0RC1 - () https://github.com/OSGeo/gdal/releases/tag/v3.13.0RC1 - Release Notes, Patch
References () https://github.com/biniamf/pocs/tree/main/gdal-gdsdfldsrch_oob-read - () https://github.com/biniamf/pocs/tree/main/gdal-gdsdfldsrch_oob-read - Exploit, Third Party Advisory
References () https://vuldb.com/submit/808128 - () https://vuldb.com/submit/808128 - Exploit, Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/362430 - () https://vuldb.com/vuln/362430 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/362430/cti - () https://vuldb.com/vuln/362430/cti - Permissions Required, VDB Entry
First Time Osgeo gdal
Osgeo
CWE CWE-125
CPE cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*:*
cpe:2.3:a:osgeo:gdal:3.13.0:beta2:*:*:*:*:*:*
cpe:2.3:a:osgeo:gdal:3.13.0:beta1:*:*:*:*:*:*

09 May 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-09 23:16

Updated : 2026-05-19 19:58


NVD link : CVE-2026-8213

Mitre link : CVE-2026-8213

CVE.ORG link : CVE-2026-8213


JSON object : View

Products Affected

osgeo

  • gdal
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-122

Heap-based Buffer Overflow

CWE-125

Out-of-bounds Read