DEBIAN-CVE-2026-3283

Source
https://security-tracker.debian.org/tracker/CVE-2026-3283
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-3283.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-3283
Upstream
Published
2026-02-27T03:16:02Z
Modified
2026-09-14T17:03:07Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

A vulnerability has been found in libvips 8.19.0. This issue affects the function vips_extract_band_build of the file libvips/conversion/extract.c. The manipulation of the argument extract_band leads to out-of-bounds read. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 24795bb3d19d84f7b6f5ed86451ad556c8f2fe70. To fix this issue, it is recommended to deploy a patch.

References

Affected packages

Debian:12 / vips

Package

Name
vips
Purl
pkg:deb/debian/vips?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.14.1-3+deb12u3

Affected versions

8.*
8.14.1-3
8.14.1-3+deb12u1
8.14.1-3+deb12u2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-3283.json"

Debian:13 / vips

Package

Name
vips
Purl
pkg:deb/debian/vips?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.16.1-1+deb13u1

Affected versions

8.*
8.16.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-3283.json"

Debian:14 / vips

Package

Name
vips
Purl
pkg:deb/debian/vips?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.18.0-3

Affected versions

8.*
8.16.1-1
8.16.1-2
8.17.3-1
8.17.3-2
8.18.0-1
8.18.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-3283.json"