#1149056 vips: CVE-2026-88360

#1149056#5
Date:
2026-09-26 11:47:14 UTC
From:
To:
Hi,

The following vulnerability was published for vips.

CVE-2026-88360[0]:
| libvips 8.19.0 contains a memory access vulnerability when
| processing little-endian PFM images. If the PFM text header length
| is not a multiple of four bytes, the mmap-based loader can expose
| pixel data at an address that is not properly aligned for float
| access. vips_avg_scan() subsequently dereferences the buffer through
| a float pointer, resulting in undefined behavior and process
| termination on strict-alignment architectures or UBSan-instrumented
| builds, leading to denial of service.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-88360
https://www.cve.org/CVERecord?id=CVE-2026-88360
[1] https://github.com/libvips/libvips/issues/5187

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1149056#10
Date:
2026-09-26 13:33:46 UTC
From:
To:
Hi Salvatore,
[...]
 Please note that the newest upstream release [1] is v8.18.7 in two
hours. There is no v8.19.0 release. The issue you link to (#5187) is
from August 16th and upstream cites this as not a security issue [2].
Even blocked this agent [3].

Regards,
Laszlo/GCS
[1] https://github.com/libvips/libvips/releases
[2] https://github.com/libvips/libvips/issues/5187#issuecomment-5829413830
[3] https://github.com/libvips/libvips/issues/5187#event-31843470458

#1149056#15
Date:
2026-09-26 13:39:36 UTC
From:
To:
Hi Laszlo,

Thanks a lot for pointing that out. Unfortunately I missed since we
have quite a lot of CVEs to handle. I have marked for now the CVE as
unimportant stating it is not a security issue.

The CVE should really be rejected :(

Regards,
Salvatore