CVE-2026-70651

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height while loading a crafted multi-page TIFF through VipsForeignLoadMagick. The vulnerable calculations in libvips/foreign/magick6load.c and libvips/foreign/magick7load.c multiply the per-page Ysize by n_frames without a checked bound, which can cause a heap buffer over-read and process crash. Most package-manager builds include libtiff and do not use this affected fallback path. This issue is fixed in version 8.18.3.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-20 21:17

Updated : 2026-08-25 16:17


NVD link : CVE-2026-70651

Mitre link : CVE-2026-70651

CVE.ORG link : CVE-2026-70651


JSON object : View

Products Affected

No product.

CWE
CWE-680

Integer Overflow to Buffer Overflow