SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02, the XWD codec resolves pixel format based on pixmap_depth but the byte-swap code uses bits_per_pixel independently. When pixmap_depth=8 (BPP8_INDEXED, 1 byte/pixel buffer) but bits_per_pixel=32, the byte-swap loop accesses memory as uint32_t*, reading/writing 4x the allocated buffer size. This is a different vulnerability from the previously reported GHSA-3g38-x2pj-mv55 (CVE-2026-27168), which addressed bytes_per_line validation. Commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02 contains a patch.
{
"cwe_ids": [
"CWE-787"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40492.json",
"cna_assigner": "GitHub_M",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"fixed": "36aa5c7ec8a2bb35f6fb867a1177a6f141156b02"
}
]
}
]
}"2026-07-15T16:00:31Z"
[
{
"signature_type": "Line",
"target": {
"file": "src/sail-codecs/xwd/xwd.c"
},
"deprecated": false,
"source": "https://github.com/happyseafox/sail/commit/36aa5c7ec8a2bb35f6fb867a1177a6f141156b02",
"id": "CVE-2026-40492-37962320",
"signature_version": "v1",
"digest": {
"line_hashes": [
"241914563982233639573845007159297089324",
"295817320788695645281346781011607923799",
"292825153532519996765145851580766437850"
],
"threshold": 0.9
}
},
{
"signature_type": "Line",
"target": {
"file": "src/sail-codecs/xwd/helpers.c"
},
"deprecated": false,
"source": "https://github.com/happyseafox/sail/commit/36aa5c7ec8a2bb35f6fb867a1177a6f141156b02",
"id": "CVE-2026-40492-4341807d",
"signature_version": "v1",
"digest": {
"line_hashes": [
"301172747459491402306297918240814752710",
"302421592605300366635941206248779060068",
"74789464625873683996409345570762591823",
"247752627975517855410946776263564758809",
"170276404050264280440372485395218640317",
"95229939895371536688137017804749238078",
"37515935817804880849288679035941040941",
"248394860716996669598131846278211538510",
"301723293624276253928488806541747997667",
"176348866057720317713467114476473176628",
"11301665131726034708162836816131527854",
"314800525921609777004113325435404543896"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "src/sail-codecs/xwd/helpers.c",
"function": "xwd_private_read_pixels"
},
"deprecated": false,
"source": "https://github.com/happyseafox/sail/commit/36aa5c7ec8a2bb35f6fb867a1177a6f141156b02",
"id": "CVE-2026-40492-6523eecd",
"signature_version": "v1",
"digest": {
"function_hash": "68601468689675830584704341915669920656",
"length": 1802.0
}
},
{
"signature_type": "Function",
"target": {
"file": "src/sail-codecs/xwd/xwd.c",
"function": "sail_codec_load_seek_next_frame_v8_xwd"
},
"deprecated": false,
"source": "https://github.com/happyseafox/sail/commit/36aa5c7ec8a2bb35f6fb867a1177a6f141156b02",
"id": "CVE-2026-40492-a9d4d239",
"signature_version": "v1",
"digest": {
"function_hash": "90113702793324592564658174144569046510",
"length": 2212.0
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-40492.json"