CVE-2025-46407
A memory corruption vulnerability exists in the BMPv3 Palette Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .bmp file, an integer overflow can be made to occur which will cause a heap-based buffer to overflow when reading the palette from the image. These conditions can allow for remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS probability
- 0.66%
- CWE
- CWE-680
- Published
- 2025-08-25
- Last modified
- 2026-03-13
Affected products
- SAIL Image Decoding Library SAIL Image Decoding Library
Weakness type
Related vulnerabilities
- CVE-2026-81647 — Out-of-bounds read vulnerability in the graphics module....
- CVE-2026-19313 — Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution
- CVE-2026-70651 — libvips: Possible integer overflow when reading multi-page TIFF images via ImageMagick
- CVE-2026-19588 — Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow...
- CVE-2026-43627 — llama.cpp b1283–b9058 Integer Overflow in llama_batch_init() Function
- CVE-2026-55200 — libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
- CVE-2026-8376 — Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
- CVE-2026-24928 — Out-of-bounds write vulnerability in the file system module....