Integer Overflow Vulnerability in Embedded Graphics Library for 32-bit Systems
CVE-2026-90596
6.9MEDIUM
What is CVE-2026-90596?
A vulnerability has been discovered in the embedded-graphics library prior to version 0.8.2, specifically affecting 32-bit systems. This flaw resides in the ImageRaw::new/bytes_per_row function, allowing for an integer overflow that can potentially be exploited by remote attackers. As a result, it is crucial for users to upgrade to the latest version to safeguard their systems. Despite being alerted to this issue via an issue report, the project maintainers have yet to provide a response.
Affected Version(s)
embedded-graphics 0.8.0
embedded-graphics 0.8.1
embedded-graphics 0.8.2
