A security vulnerability has been detected in SerenityOS up to 3d83e4509fd20d7438e1ae8470ffe668c136229c. Affected by this vulnerability is the function decode_bmp_pixel_data of the file Userland/Libr…
Low CVSS 3.1
Summary
A security vulnerability has been detected in SerenityOS up to 3d83e4509fd20d7438e1ae8470ffe668c136229c. Affected by this vulnerability is the function decode_bmp_pixel_data of the file Userland/Libraries/LibGfx/ImageFormats/BMPLoader.cpp of the component LibGfx. The manipulation of the argument height leads to integer overflow. The attack is possible to be carried out remotely. The attack's complexity is rated as high. The exploitation appears to be difficult. The exploit has been disclosed pu…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/SerenityOS/serenity/commit/007041bb2dd6d140c9e707caddfb0a49ecf96469
- https://github.com/SerenityOS/serenity/issues/26957
- https://github.com/SerenityOS/serenity/pull/26958
- https://vuldb.com/cve/CVE-2026-94030
- https://vuldb.com/submit/945895
- https://vuldb.com/vuln/407958
- https://vuldb.com/vuln/407958/cti
Timeline
- nvd_ingest NVD