#1142677 cimg: CVE-2026-47667

Package:
src:cimg
Source:
src:cimg
Submitter:
Salvatore Bonaccorso
Date:
2026-07-30 17:37:02 UTC
Severity:
normal
Tags:
#1142677#5
Date:
2026-07-24 06:15:31 UTC
From:
To:
Hi,

The following vulnerability was published for cimg.

CVE-2026-47667[0]:
| CImg Library is a C++ library for image processing. Prior to version
| 4.0.0 in `_load_analyze()`, the header_size field is read as an
| `unsigned int` from the first 4 bytes of an Analyze/NIfTI file and
| passed directly to `new unsigned char[header_size]` without being
| bounded against the actual file size. A value up to ~4 GB is
| accepted. If the subsequent `fread` returns `short`  as it will for
| any malformed file), the function throws a `CImgIOException` and the
| allocated buffer is never freed. A 6-byte crafted file is sufficient
| to trigger an allocation of ~1.3 GB per call, with the full
| allocation leaked on every error path. The issue is reachable via
| `load_analyze()` and the generic `load()` when the file extension is
| .hdr, .img, or .nii. Version 4.0.0 fixes the issue.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-47667
https://www.cve.org/CVERecord?id=CVE-2026-47667
[1] https://github.com/GreycLab/CImg/issues/480
[2] https://github.com/GreycLab/CImg/security/advisories/GHSA-rmfc-grgj-qwhv
[4] https://github.com/GreycLab/CImg/commit/6a69bf725ffd111a4c7dc61cc15e3661abd158ee

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore