Image Buffer Overflow in SAIL Library Affects Multiple Platforms
CVE-2026-54626
9.8CRITICAL
What is CVE-2026-54626?
The SAIL library, used for loading and saving images across platforms, contains a vulnerability that affects the handling of color-mapped run-length-encoded TGA images. In versions 0.9.10 and earlier, a flaw in the TGA_INDEXED_RLE handling allows an attacker to exploit a crafted file, leading to potential heap corruption by writing beyond the allocated memory buffer. This vulnerability is a consequence of insufficient input validation, providing an avenue for crashes or unintended code execution. It has been addressed in version 1.0.0.
Affected Version(s)
sail < 1.0.0
