Junglewise Threat Intelligence

CVE-2026-70653: libvips Radiance RLE decoder heap disclosure

CVE-2026-70653 · Severity: info · Published 2026-08-20

Technologies: Libvips. Vendors: Libvips.

Executive brief

libvips is a widely-used image processing library. A vulnerability in its old-style Radiance image format decoder allows an attacker to read uninitialized heap memory (typically other image data) by crafting a malicious Radiance image file. While the exposure is small (4 bytes), this can leak sensitive image data if the library processes untrusted image inputs.

Technical details

The vulnerability is a heap buffer over-read in the old-style Radiance RLE decoder in libvips/foreign/radiance.c. When processing a repeat marker at the beginning of a scanline in the scanline_read_old function, the code reads from q[-1] before any prior pixel has been initialized, resulting in disclosure of 4 bytes of adjacent heap memory. The vulnerability requires only that a crafted Radiance image be loaded via VipsForeignLoadRad—no authentication or special conditions. An attacker can use this to leak adjacent heap data, most commonly other image data. The fix was implemented in version 8.18.3 by deprecating the old-style RLE decoder.

Affected products

  • libvips libvips before 8.18.3

Timeline

  • 2026-05-13: patched: Fix merged in version 8.18.3
  • 2026-08-20: disclosed

References

Related threats