Vulnerability Description
libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height while loading a crafted multi-page TIFF through VipsForeignLoadMagick. The vulnerable calculations in libvips/foreign/magick6load.c and libvips/foreign/magick7load.c multiply the per-page Ysize by n_frames without a checked bound, which can cause a heap buffer over-read and process crash. Most package-manager builds include libtiff and do not use this affected fallback path. This issue is fixed in version 8.18.3.
Related Weaknesses (CWE)
References
- https://github.com/libvips/libvips/commit/05719ca3d5852acdeb6714de2e8e769c9a5d2c
- https://github.com/libvips/libvips/pull/5040
- https://github.com/libvips/libvips/releases/tag/v8.18.3
- https://github.com/libvips/libvips/security/advisories/GHSA-7p29-wg2h-36q4
FAQ
What is CVE-2026-70651?
CVE-2026-70651 is a documented vulnerability. libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height whi...
How severe is CVE-2026-70651?
CVSS scoring is not yet available for CVE-2026-70651. Check NVD for updates.
Is there a patch for CVE-2026-70651?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.