LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-44636

saitoha · libsixel

Published
CVSS7.4
Severityhigh
WeaknessCWE-122
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's allocation size calculation can lead to a heap buffer overflow. The public sixel_encode entry point validates only that width and height are greater than zero, with no upper bound. width and height are multiplied as plain int when computing the allocation size for paletted_pixels and normalized_pixels. Any caller that asks libsixel to encode a pixel buffer with width times height greater than INT_MAX (about 2.15 billion) will hit a wrapped allocation size; under the right wrap, the malloc succeeds with a buffer much smaller than the encoder exp

References

← Back to the CVE Tracker

Our coverage of CVE-2026-44636

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-44636.