JLSEC-2026-771

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-771.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-771.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-771
Upstream
  • EUVD-2026-28948
Published
2026-07-15T21:25:44.755Z
Modified
2026-07-18T00:02:23.425852177Z
Severity
  • 4.3 (Medium) CVSS_V2 - AV:L/AC:L/Au:S/C:P/I:P/A:P CVSS Calculator
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
OSGeo gdal has a heap-based buffer overflow
Details

A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWapi.c. Executing a manipulation can lead to heap-based buffer overflow. The attack requires local access. The exploit has been published and may be used. Upgrading to version 3.13.0RC1 addresses this issue. This patch commit sha is 3e04c0385630e4d42517046d9a4967dfccfeb7fd. The affected component should be upgraded.

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8212",
            "id": "CVE-2026-8212",
            "published": "2026-05-09T23:16:33.113Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-8212",
            "database_specific": {
                "status": "Analyzed"
            },
            "modified": "2026-06-17T11:03:38.877Z",
            "imported": "2026-07-17T22:39:26.744Z"
        },
        {
            "html_url": "https://github.com/advisories/GHSA-r5m4-5vww-w9f5",
            "id": "GHSA-r5m4-5vww-w9f5",
            "published": "2026-05-10T00:33:21Z",
            "url": "https://api.github.com/advisories/GHSA-r5m4-5vww-w9f5",
            "modified": "2026-05-29T22:23:31Z",
            "imported": "2026-07-17T22:39:26.908Z"
        },
        {
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28948",
            "modified": "2026-05-11T14:56:32Z",
            "published": "2026-05-09T22:30:12Z",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-28948",
            "id": "EUVD-2026-28948",
            "imported": "2026-07-17T22:39:36.730Z"
        }
    ]
}
References

Affected packages

Julia / GDAL_jll

Package

Name
GDAL_jll
Purl
pkg:julia/GDAL_jll?uuid=a7073274-a066-55f0-b90d-d619367d196c

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
305.1300.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-771.json"