Bug 2540111 (CVE-2026-88360)

Summary: CVE-2026-88360 libvips: libvips: Denial of Service via Malformed PFM Image Processing
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in libvips, an image processing library. When handling specially crafted little-endian PFM (Portable Float Map) images, an attacker could trigger an unaligned memory access. This occurs if the image's text header length is not a multiple of four bytes, causing the loader to expose pixel data at an incorrect memory address. Such unaligned access can lead to undefined behavior and cause the application to terminate, resulting in a denial of service (DoS) for affected systems.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2541377    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-24 14:22:55 UTC
libvips 8.19.0 contains a memory access vulnerability when processing little-endian PFM images. If the PFM text header length is not a multiple of four bytes, the mmap-based loader can expose pixel data at an address that is not properly aligned for float access. vips_avg_scan() subsequently dereferences the buffer through a float pointer, resulting in undefined behavior and process termination on strict-alignment architectures or UBSan-instrumented builds, leading to denial of service.