Executive brief
CImg is a C++ library used by developers to process and load images. A vulnerability in how it handles specific medical and scientific image formats (Analyze/NIfTI) allows an attacker to crash an application or exhaust its memory by providing a specially crafted, very small file. This can lead to a denial-of-service condition where the affected software becomes unresponsive or stops working entirely.
Technical details
A vulnerability exists in the `_load_analyze()` function of the CImg library due to improper validation of the `header_size` field. The function reads a 4-byte `unsigned int` from the start of an Analyze/NIfTI file (.hdr, .img, .nii) and uses it to allocate a buffer via `new[]` without verifying it against the actual file size. If the file is malformed (e.g., shorter than the declared header size), a `CImgIOException` is thrown, but the allocated memory is never freed. An attacker can trigger a ~1.3 GB allocation and subsequent leak using a file as small as 6 bytes, leading to rapid memory exhaustion (OOM). The issue is fixed in version 4.0.0.
Affected products
- GreycLab CImg < 4.0.0
Timeline
- 2026-05-11: disclosed: Issue reported on GitHub
- 2026-05-18: patched: Fix committed to repository
- 2026-05-19: advisory: GitHub Security Advisory published
- 2026-07-21: advisory: NVD published CVE-2026-47667