Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 25 Feb 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in libvips up to 8.18.0. The affected element is the function vips_foreign_load_matrix_file_is_a/vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. Executing a manipulation can lead to memory corruption. The attack needs to be launched locally. This patch is called d4ce337c76bff1b278d7085c3c4f4725e3aa6ece. A patch should be applied to remediate this issue. | |
| Title | libvips matrixload.c vips_foreign_load_matrix_header memory corruption | |
| First Time appeared |
Libvips
Libvips libvips |
|
| Weaknesses | CWE-119 | |
| CPEs | cpe:2.3:a:libvips:libvips:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Libvips
Libvips libvips |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-02-25T20:28:56.023Z
Reserved: 2026-02-24T19:53:43.308Z
Link: CVE-2026-3145
No data.
Status : Analyzed
Published: 2026-02-25T03:16:07.193
Modified: 2026-02-25T20:56:39.700
Link: CVE-2026-3145
No data.
OpenCVE Enrichment
Updated: 2026-04-17T15:45:15Z