A heap-based buffer overflow in Clmg before 3.3.3 can occur via a crafted file to cimg_library::CImg<unsigned char>::loadanalyze.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26540.json"
}{
"source": [
"DESCRIPTION",
"CPE_RANGE"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.3.3"
}
],
"cpe": "cpe:2.3:a:cimg:cimg:*:*:*:*:*:*:*:*"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-26540.json"
"2026-08-08T08:29:55Z"
[
{
"digest": {
"line_hashes": [
"155669739585643622889137027896997700532",
"88568925240059472017629875457572398671",
"321192010424700383896782719236117411911",
"20862745565239506495325848946152351854",
"86902541839714401340114288423925871836",
"115851533477071982017476682743649757827",
"221883510274202488777259975584335518668",
"47736392895373558861172942918092634579"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2024-26540-888649b9",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/greyclab/cimg/commit/157800186587ed368cd2cb30e0974bc079cbe556",
"target": {
"file": "CImg.h"
}
}
]