CVE-2026-47667
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
CImg Library is a C++ library for image processing. Prior to version 4.0.0 in _load_analyze(), the header_size field is read as an unsigned int from the first 4 bytes of an Analyze/NIfTI file and passed directly to new unsigned char[header_size] without being bounded against the actual file size. A value up to ~4 GB is accepted. If the subsequent fread returns short as it will for any malformed file), the function throws a CImgIOException and the allocated buffer is never freed. A 6-byte crafted file is sufficient to trigger an allocation of ~1.3 GB per call, with the full allocation leaked on every error path. The issue is reachable via load_analyze() and the generic load() when the file extension is .hdr, .img, or .nii. Version 4.0.0 fixes the issue.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GreycLab | CImg | < 4.0.0 | affected |
Weaknesses
- CWE-401: CWE-401: Missing Release of Memory after Effective Lifetime
- CWE-789: CWE-789: Memory Allocation with Excessive Size Value
- CWE-1284: CWE-1284: Improper Validation of Specified Quantity in Input
References
- https://github.com/GreycLab/CImg/security/advisories/GHSA-rmfc-grgj-qwhv
- https://github.com/GreycLab/CImg/issues/480
- https://github.com/GreycLab/CImg/commit/6a69bf725ffd111a4c7dc61cc15e3661abd158ee
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.