libvips Integer Overflow Vulnerability in GIF Loading on 32-Bit Systems

Vulnerability

A vulnerability in libvips versions through 8.18.0 on 32-bit systems allows the 'gifload' operation to miscalculate image dimensions, resulting in an integer overflow. This issue has been addressed in version 8.18.1.

Impact

The vulnerability can lead to a denial-of-service condition by causing a crash or unexpected behavior in applications that use libvips for image processing.

Remediation

Users can update to libvips version 8.18.1 or later to address this vulnerability. Alternatively, the 'VipsForeignLoadNsgif' operation can be blocked using 'vips_operation_block_set', available in most language bindings.

Added: Jul 20, 2026, 6:30 PM
Updated: Jul 20, 2026, 6:30 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
0.6
exploitability
5.0
remediation
7.9
relevance
9.9
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.