libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vipsforeignsaveuhdrsetrawhdr when a pipeline enlarges an incoming JPEG to a very large output before encoding a gain map through VipsForeignSaveUhdr. The undersized allocation can cause a heap buffer over-read that may disclose adjacent data or crash the process. This issue is fixed in version 8.18.3.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-126"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70652.json"
}"2026-08-24T03:59:14Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70652.json"
[
{
"deprecated": false,
"target": {
"file": "libvips/foreign/radiance.c"
},
"signature_type": "Line",
"source": "https://github.com/libvips/libvips/commit/3664cfc5dc2c5661288f5bf5a85ccc51c64c1626",
"digest": {
"line_hashes": [
"40871188566960555797534865343993917120",
"280583468346626059971461642282471659907",
"124457516850962973310175479744249140645",
"328053393552607056949457160698094811715",
"215634287215946805611721991023061710430",
"156768635521381228100771632092021262850",
"277582039530558050549102845751760158295",
"293496822736095924310907936123479200764",
"247399218563492718961184865847735965900",
"335249549507646226668533406698177255556",
"39003126028108026901725344741125630115",
"319954858964960260251026803592065571652",
"287170327211599960049231835358937974244",
"93930203671943223743569148747746365986"
],
"threshold": 0.9
},
"signature_version": "v1",
"id": "CVE-2026-70652-4e5493d3"
},
{
"deprecated": false,
"target": {
"file": "libvips/foreign/uhdrsave.c"
},
"signature_type": "Line",
"source": "https://github.com/libvips/libvips/commit/cff17794f0698a4f47c74bb31c9700b2c83252a8",
"digest": {
"line_hashes": [
"328514610236387960317546307782831870221",
"111467087028955450532628775949531223436",
"160519221309831131626181757507565771342",
"65726386350385193732358062475643311346"
],
"threshold": 0.9
},
"signature_version": "v1",
"id": "CVE-2026-70652-5d75b059"
},
{
"deprecated": false,
"target": {
"function": "scanline_read_old",
"file": "libvips/foreign/radiance.c"
},
"signature_type": "Function",
"source": "https://github.com/libvips/libvips/commit/3664cfc5dc2c5661288f5bf5a85ccc51c64c1626",
"digest": {
"length": 994.0,
"function_hash": "72490777654407013462939268128658569853"
},
"signature_version": "v1",
"id": "CVE-2026-70652-aed2a489"
},
{
"deprecated": false,
"target": {
"function": "vips_foreign_save_uhdr_set_raw_hdr",
"file": "libvips/foreign/uhdrsave.c"
},
"signature_type": "Function",
"source": "https://github.com/libvips/libvips/commit/cff17794f0698a4f47c74bb31c9700b2c83252a8",
"digest": {
"length": 880.0,
"function_hash": "29044277138172826812961938730596853197"
},
"signature_version": "v1",
"id": "CVE-2026-70652-f680b4fb"
}
]