Bug 2497328 (CVE-2026-53877) - CVE-2026-53877 django: Django: Information disclosure via heap buffer over-read in GDALRaster
Summary: CVE-2026-53877 django: Django: Information disclosure via heap buffer over-re...
Keywords:
Status: NEW
Alias: CVE-2026-53877
Deadline: 2026-07-07
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-06 11:43 UTC by OSIDB Bzimport
Modified: 2026-07-18 08:30 UTC (History)
31 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)
0002-5.2.x-Fixed-CVE-2026-53877-Prevented-heap-buffer-ove.patch (3.11 KB, patch)
2026-07-06 12:11 UTC, Yadnyawalk Tale
no flags Details | Diff
0002-6.0.x-Fixed-CVE-2026-53877-Prevented-heap-buffer-ove.patch (4.06 KB, patch)
2026-07-06 12:11 UTC, Yadnyawalk Tale
no flags Details | Diff
0002-6.1.x-Fixed-CVE-2026-53877-Prevented-heap-buffer-ove.patch (4.06 KB, patch)
2026-07-06 12:11 UTC, Yadnyawalk Tale
no flags Details | Diff
0002-Fixed-CVE-2026-53877-Prevented-heap-buffer-over-read.patch (4.05 KB, patch)
2026-07-06 12:11 UTC, Yadnyawalk Tale
no flags Details | Diff

Description OSIDB Bzimport 2026-07-06 11:43:25 UTC
A flaw was found in Django. When django.contrib.gis.gdal.GDALRaster is instantiated with a bytes object representing a raster file, the vsi_buffer property can read approximately 32 bytes beyond the allocated buffer. This may disclose adjacent heap memory or, in rare cases, cause a segmentation fault.

Comment 1 Yadnyawalk Tale 2026-07-06 12:11:51 UTC
Created attachment 2147812 [details]
0002-5.2.x-Fixed-CVE-2026-53877-Prevented-heap-buffer-ove.patch

Comment 2 Yadnyawalk Tale 2026-07-06 12:11:53 UTC
Created attachment 2147813 [details]
0002-6.0.x-Fixed-CVE-2026-53877-Prevented-heap-buffer-ove.patch

Comment 3 Yadnyawalk Tale 2026-07-06 12:11:55 UTC
Created attachment 2147814 [details]
0002-6.1.x-Fixed-CVE-2026-53877-Prevented-heap-buffer-ove.patch

Comment 4 Yadnyawalk Tale 2026-07-06 12:11:57 UTC
Created attachment 2147815 [details]
0002-Fixed-CVE-2026-53877-Prevented-heap-buffer-over-read.patch


Note You need to log in before you can comment on or make changes to this bug.