Memory Mismanagement in SAIL Image Loading Library
CVE-2026-40492
9.8CRITICAL
What is CVE-2026-40492?
SAIL is an image loading library that encounters a memory mismanagement issue within its XWD codec. The vulnerability arises when the codec resolves pixel formats based on pixmap_depth, while incorrectly applying byte-swapping logic using bits_per_pixel. This discrepancy can lead to unauthorized access to memory, resulting in buffer overflows and potential data corruption. The issue was addressed in commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02, which includes a fix to enhance the security and robustness of the library.
Affected Version(s)
sail < 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02
