CVE-2026-8213

Source
https://cve.org/CVERecord?id=CVE-2026-8213
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8213.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-8213
Aliases
Downstream
Published
2026-05-09T23:00:17.283Z
Modified
2026-08-07T21:14:20.434446Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
OSGeo gdal Grid File GDapi.c GDSDfldsrch heap-based overflow
Details

A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4/hdf-eos/GDapi.c of the component Grid File Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 3.13.0RC1 can resolve this issue. The identifier of the patch is 3e04c0385630e4d42517046d9a4967dfccfeb7fd. It is suggested to upgrade the affected component.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-119",
        "CWE-122"
    ],
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "3.13.0dev-4"
                },
                {
                    "last_affected": "3.13.0dev-4"
                }
            ]
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8213.json"
}
References

Affected packages

Git / github.com/osgeo/gdal

Affected ranges

Type
GIT
Repo
https://github.com/osgeo/gdal
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
Fixed
Database specific
{
    "source": [
        "CPE_RANGE",
        "CPE_STRING",
        "REFERENCES"
    ],
    "cpe": [
        "cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:osgeo:gdal:3.13.0:beta1:*:*:*:*:*:*",
        "cpe:2.3:a:osgeo:gdal:3.13.0:beta2:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.12.4"
        },
        {
            "introduced": "3.13.0-beta1"
        },
        {
            "last_affected": "3.13.0-beta1"
        },
        {
            "introduced": "3.13.0-beta2"
        },
        {
            "last_affected": "3.13.0-beta2"
        }
    ]
}

Affected versions

2.*
2.4.4
3.*
3.0.3
3.13.0-beta1
3.13.0-beta2
v2.*
v2.3.0beta1
v2.4.0
v3.*
v3.1.0RC1
v3.11.0beta1
v3.12.0RC1
v3.12.0beta0
v3.12.0beta1
v3.12.0rc0
v3.12.1
v3.12.1RC1
v3.12.2
v3.12.2RC1
v3.12.3
v3.12.3RC1
v3.12.3RC2
v3.12.4
v3.12.4RC1
v3.13.0beta1
v3.3.0
v3.3.0RC1
v3.3.0beta1
v3.5.0RC1
v3.6.0RC1
v3.8.0RC1
v3.8.0beta1

Database specific

vanir_signatures_modified
"2026-08-07T21:14:20Z"
vanir_signatures
[
    {
        "target": {
            "file": "frmts/hdf4/hdf-eos/GDapi.c"
        },
        "digest": {
            "line_hashes": [
                "167182038433977325088140875918359002134",
                "326107720542469682361036124829195640199",
                "145211092907363323265357074335233750441",
                "191590602733504516798627237624263597385",
                "65435948641469255597402762770679970626",
                "251844773267004694610613087050398686949"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "signature_type": "Line",
        "deprecated": false,
        "id": "CVE-2026-8213-364a1ce3",
        "source": "https://github.com/osgeo/gdal/commit/3e04c0385630e4d42517046d9a4967dfccfeb7fd"
    },
    {
        "target": {
            "file": "frmts/hdf4/hdf-eos/SWapi.c"
        },
        "digest": {
            "line_hashes": [
                "47874982481244558623088493222637245073",
                "33437425289549441688188381091884953329",
                "248934914709926534082598085852344720376",
                "191590602733504516798627237624263597385",
                "65435948641469255597402762770679970626",
                "251844773267004694610613087050398686949"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "signature_type": "Line",
        "deprecated": false,
        "id": "CVE-2026-8213-49b53314",
        "source": "https://github.com/osgeo/gdal/commit/3e04c0385630e4d42517046d9a4967dfccfeb7fd"
    },
    {
        "target": {
            "function": "SWSDfldsrch",
            "file": "frmts/hdf4/hdf-eos/SWapi.c"
        },
        "digest": {
            "length": 2208.0,
            "function_hash": "84405029591409210647790526936196376142"
        },
        "signature_version": "v1",
        "signature_type": "Function",
        "deprecated": false,
        "id": "CVE-2026-8213-98b5d44a",
        "source": "https://github.com/osgeo/gdal/commit/3e04c0385630e4d42517046d9a4967dfccfeb7fd"
    },
    {
        "target": {
            "function": "GDSDfldsrch",
            "file": "frmts/hdf4/hdf-eos/GDapi.c"
        },
        "digest": {
            "length": 2255.0,
            "function_hash": "102204458867495531352866937965636611226"
        },
        "signature_version": "v1",
        "signature_type": "Function",
        "deprecated": false,
        "id": "CVE-2026-8213-d5bacd93",
        "source": "https://github.com/osgeo/gdal/commit/3e04c0385630e4d42517046d9a4967dfccfeb7fd"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8213.json"