Integer Overflow Vulnerability in embedded-graphics by embedded-graphics
CVE-2026-90593

6.9MEDIUM

Key Information:

Vendor
CVE Published:
13 September 2026

What is CVE-2026-90593?

The embedded-graphics library, specifically in the ImageRaw::draw_sub_image function of src/image/image_raw.rs, contains a critical vulnerability that allows for integer overflow by manipulating the argument width. This flaw enables attackers to exploit the vulnerability remotely, potentially leading to unauthorized access or execution of malicious code. Despite the vulnerability being reported through an issue, the maintainers have not yet addressed the problem, leaving systems utilizing the affected versions exposed to risks.

Affected Version(s)

embedded-graphics 0.8.0

embedded-graphics 0.8.1

embedded-graphics 0.8.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Default01 (VulDB User)
VulDB CNA Team
.