« Volver al listado

CVE-2026-33020

Estado: AnalizadaAlta (7.1)—

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow which leads to a heap buffer overflow via sixel_frame_convert_to_rgb888() in frame.c, where allocation size and pointer offset computations for palettised images (PAL1, PAL2, PAL4) are performed using int arithmetic before casting to size_t.

Leer descripción completaMostrar menos

For images whose pixel count exceeds INT_MAX / 4, the overflow produces an undersized heap allocation for the conversion buffer and a negative pointer offset for the normalization sub-buffer, after which sixel_helper_normalize_pixelformat() writes the full image data starting from the invalid pointer, causing massive heap corruption confirmed by ASAN. An attacker providing a specially crafted large palettised PNG can corrupt the heap of the victim process, resulting in a reliable crash and potential arbitrary code execution. This issue has been fixed in version 1.8.7-r1.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Archivo PNG especialmente diseñado requiere interacción del usuario (abrir/procesar imagen); AV:L + UI:R confirma T1203. Corrupción de heap permite ejecución de código arbitraria (T1059).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-33020",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-33020",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-15T13:30:43.489988Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "saitoha",
          "product": "libsixel",
          "versions": [
            {
              "status": "affected",
              "version": "< 1.8.7-r1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-04-14T22:16:30.543",
  "references": [
    {
      "url": "https://github.com/saitoha/libsixel/releases/tag/v1.8.7-r1",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/saitoha/libsixel/security/advisories/GHSA-2xgm-4x47-2x2p",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/saitoha/libsixel/security/advisories/GHSA-2xgm-4x47-2x2p",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-122"
        },
        {
          "lang": "en",
          "value": "CWE-190"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow which leads to a heap buffer overflow via sixel_frame_convert_to_rgb888() in frame.c, where allocation size and pointer offset computations for palettised images (PAL1, PAL2, PAL4) are performed using int arithmetic before casting to size_t. For images whose pixel count exceeds INT_MAX / 4, the overflow produces an undersized heap allocation for the conversion buffer and a negative pointer offset for the normalization sub-buffer, after which sixel_helper_normalize_pixelformat() writes the full image data starting from the invalid pointer, causing massive heap corruption confirmed by ASAN. An attacker providing a specially crafted large palettised PNG can corrupt the heap of the victim process, resulting in a reliable crash and potential arbitrary code execution.\nThis issue has been fixed in version 1.8.7-r1."
    },
    {
      "lang": "es",
      "value": "libsixel es una implementación de codificador/decodificador SIXEL derivada de sixel de kmiya. Las versiones 1.8.7 y anteriores contienen un desbordamiento de entero que conduce a un desbordamiento de búfer de montón a través de sixel_frame_convert_to_rgb888() en frame.c, donde los cálculos de tamaño de asignación y desplazamiento de puntero para imágenes paletizadas (PAL1, PAL2, PAL4) se realizan utilizando aritmética de enteros antes de la conversión a size_t. Para imágenes cuyo recuento de píxeles excede INT_MAX / 4, el desbordamiento produce una asignación de montón de tamaño insuficiente para el búfer de conversión y un desplazamiento de puntero negativo para el sub-búfer de normalización, después de lo cual sixel_helper_normalize_pixelformat() escribe los datos completos de la imagen comenzando desde el puntero inválido, causando una corrupción masiva del montón confirmada por ASAN. Un atacante que proporciona un PNG paletizado grande especialmente diseñado puede corromper el montón del proceso víctima, lo que resulta en un fallo fiable y una potencial ejecución de código arbitrario. Este problema ha sido solucionado en la versión 1.8.7-r1."
    }
  ],
  "lastModified": "2026-07-25T11:10:00.100",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:saitoha:libsixel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E16EAA6A-544F-4D16-829D-1B7C9979EA6A",
              "versionEndExcluding": "1.8.7-r1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}