Stack-based Buffer Overflow in GDAL NetCDF Driver Affects OSGeo
CVE-2026-49014

7.4HIGH

Key Information:

Vendor

Gdal

Status
Vendor
CVE Published:
27 May 2026

What is CVE-2026-49014?

The GDAL library versions 3.1.0 through 3.13.0 contain a vulnerability in the netCDF driver, specifically within the scanForGeometryContainers function. This flaw allows an attacker to perform a stack-based buffer overflow by embedding an oversized geometry attribute in a specially crafted NetCDF file. Since the vulnerability arises from the lack of validation on the length of the geometry attribute, successful exploitation can result in arbitrary code execution on the server running the affected GDAL versions, potentially leading to unauthorized access or control over the affected system.

Affected Version(s)

GDAL 3.1.0 <= 3.13.0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.