A heap-based buffer overflow in the UHDR encoder can happen due to truncation of a value and it would allow an out of bounds write.
================================================================
==2158399==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x521000039500 at pc 0x562a4a42f968 bp 0x7ffcca4ed6c0 sp 0x7ffcca4ed6b0
WRITE of size 1 at 0x521000039500 thread T0
{
"sources": [
{
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-30931",
"database_specific": {
"status": "Analyzed"
},
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30931",
"published": "2026-03-10T07:44:57.303Z",
"id": "CVE-2026-30931",
"modified": "2026-06-17T10:33:10.360Z",
"imported": "2026-07-30T14:08:46.269Z"
},
{
"url": "https://api.github.com/advisories/GHSA-h95r-c8c7-mrwx",
"html_url": "https://github.com/advisories/GHSA-h95r-c8c7-mrwx",
"published": "2026-03-12T14:15:44Z",
"id": "GHSA-h95r-c8c7-mrwx",
"modified": "2026-03-12T14:15:45Z",
"imported": "2026-07-30T14:10:17.755Z"
},
{
"id": "EUVD-2026-10397",
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-10397",
"published": "2026-03-09T21:47:48Z",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-10397",
"modified": "2026-03-10T14:53:10Z",
"imported": "2026-07-30T14:08:54.529Z"
}
],
"license": "CC-BY-4.0"
}