libvips Buffer Overflow Vulnerability in TIFF Load Operation

Vulnerability

A heap-based buffer overflow vulnerability has been identified in libvips, a fast image processing library, in versions through 8.18.1. The issue arises in the 'tiffload' operation, where the library could incorrectly assess the number of channels in JPEG or JPEG2000-encoded tiles within TIFF images. This miscalculation can lead to a buffer overflow.

Impact

Exploitation of this vulnerability could result in a heap-based buffer overflow, a common vulnerability type that can lead to arbitrary code execution or memory corruption.

Remediation

Users can update to libvips version 8.18.2 or later, where this vulnerability has been patched. Alternatively, the 'VipsForeignLoadTiff' operation can be blocked using 'vips_operation_block_set', available in most language bindings.

Added: Jul 20, 2026, 6:24 PM
Updated: Jul 20, 2026, 6:24 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
0.6
exploitability
5.3
remediation
8.3
relevance
9.9
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.