Heap Overflow Vulnerability in SAIL Image Processing Library by HappySeaFox
CVE-2026-54692

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54692?

The SAIL image processing library prior to version 1.0.0 contains a vulnerability in its handling of XBM image files. Specifically, the function sail_codec_load_frame_v8_xbm() mismanages memory allocation for decoded pixel buffers, leading to a heap overwrite when processing files with an odd row stride. This flaw allows for potential corruption of process state, causing application crashes and may enable arbitrary code execution in vulnerable applications. The issue has been rectified in version 1.0.0, highlighting the importance of upgrading to secure versions.

Affected Version(s)

sail < 1.0.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.