CVE-2026-33019
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow leading to an out-of-bounds heap read in the --crop option handling of img2sixel, where positive coordinates up to INT_MAX are accepted without overflow-safe bounds checking.
Leer descripción completaMostrar menos
In sixel_encoder_do_clip(), the expression clip_w + clip_x overflows to a large negative value when clip_x is INT_MAX, causing the bounds guard to be skipped entirely, and the unclamped coordinate is passed through sixel_frame_clip() to clip(), which computes a source pointer far beyond the image buffer and passes it to memmove(). An attacker supplying a specially crafted crop argument with any valid image can trigger an out-of-bounds read in the heap, resulting in a reliable crash and potential information disclosure. This issue has been fixed in version 1.8.7-r1.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1203Exploitation for Client Executionexecution85 % - Impacto principal
T1005Data from Local Systemcollection80 %
Vector CVSS AV:L UI:R (acceso local, requiere interacción usuario) apunta a T1203. El overflow en --crop al procesar imagen preparada causa lectura OOB (T1005) revelando datos en heap.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-125, CWE-190
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-33019",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-33019",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-04-15T18:54:19.432280Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "saitoha",
"product": "libsixel",
"versions": [
{
"status": "affected",
"version": "< 1.8.7-r1"
}
]
}
]
}
],
"published": "2026-04-14T22:16:30.380",
"references": [
{
"url": "https://github.com/saitoha/libsixel/releases/tag/v1.8.7-r1",
"tags": [
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/saitoha/libsixel/security/advisories/GHSA-c854-ffg9-g72c",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/saitoha/libsixel/security/advisories/GHSA-c854-ffg9-g72c",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-125"
},
{
"lang": "en",
"value": "CWE-190"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow leading to an out-of-bounds heap read in the --crop option handling of img2sixel, where positive coordinates up to INT_MAX are accepted without overflow-safe bounds checking. In sixel_encoder_do_clip(), the expression clip_w + clip_x overflows to a large negative value when clip_x is INT_MAX, causing the bounds guard to be skipped entirely, and the unclamped coordinate is passed through sixel_frame_clip() to clip(), which computes a source pointer far beyond the image buffer and passes it to memmove(). An attacker supplying a specially crafted crop argument with any valid image can trigger an out-of-bounds read in the heap, resulting in a reliable crash and potential information disclosure. This issue has been fixed in version 1.8.7-r1."
},
{
"lang": "es",
"value": "libsixel es una implementación de codificador/decodificador SIXEL derivada de sixel de kmiya. Las versiones 1.8.7 y anteriores contienen un desbordamiento de entero que conduce a una lectura fuera de límites en el heap en el manejo de la opción '--crop' de img2sixel, donde se aceptan coordenadas positivas hasta INT_MAX sin verificación de límites segura contra desbordamientos. En sixel_encoder_do_clip(), la expresión clip_w + clip_x desborda a un valor negativo grande cuando clip_x es INT_MAX, haciendo que la protección de límites se omita por completo, y la coordenada no restringida se pasa a través de sixel_frame_clip() a clip(), que calcula un puntero de origen mucho más allá del búfer de imagen y lo pasa a memmove(). Un atacante que proporciona un argumento de recorte ('crop') especialmente diseñado con cualquier imagen válida puede desencadenar una lectura fuera de límites en el heap, lo que resulta en un fallo ('crash') fiable y una potencial revelación de información. Este problema ha sido solucionado en la versión 1.8.7-r1."
}
],
"lastModified": "2026-07-25T10:10:00.167",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:saitoha:libsixel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E16EAA6A-544F-4D16-829D-1B7C9979EA6A",
"versionEndExcluding": "1.8.7-r1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}