Hi,
The following vulnerability was published for vips.
CVE-2026-88360[0]:
| libvips 8.19.0 contains a memory access vulnerability when
| processing little-endian PFM images. If the PFM text header length
| is not a multiple of four bytes, the mmap-based loader can expose
| pixel data at an address that is not properly aligned for float
| access. vips_avg_scan() subsequently dereferences the buffer through
| a float pointer, resulting in undefined behavior and process
| termination on strict-alignment architectures or UBSan-instrumented
| builds, leading to denial of service.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-88360
https://www.cve.org/CVERecord?id=CVE-2026-88360
[1] https://github.com/libvips/libvips/issues/5187
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore