{"id":"MGASA-2026-0237","summary":"Updated vips packages fix security vulnerabilities","details":"This update fixes several security issues:\nA flaw has been found in libvips up to 8.18.0. The affected element is\nthe function\nvips_foreign_load_matrix_file_is_a/vips_foreign_load_matrix_header of\nthe file libvips/foreign/matrixload.c. Executing a manipulation can lead\nto memory corruption. The attack needs to be launched locally.\n(CVE-2026-3145)\nA vulnerability has been found in libvips up to 8.18.0. The impacted\nelement is the function vips_foreign_load_matrix_header of the file\nlibvips/foreign/matrixload.c. The manipulation leads to null pointer\ndereference. The attack needs to be performed locally. (CVE-2026-3146)\nA vulnerability was found in libvips up to 8.18.0. This affects the\nfunction vips_foreign_load_csv_build of the file\nlibvips/foreign/csvload.c. The manipulation results in heap-based buffer\noverflow. The attack requires a local approach. The exploit has been\nmade public and could be used. (CVE-2026-3147)\nA security vulnerability has been detected in libvips up to 8.18.2. The\naffected element is the function im_minpos_vec of the file\nlibvips/deprecated/vips7compat.c of the component nip2 Handler. Such\nmanipulation of the argument n leads to heap-based buffer overflow. An\nattack has to be approached locally. The exploit has been disclosed\npublicly and may be used. (CVE-2026-6491)\n","modified":"2026-07-08T16:45:05.069461169Z","published":"2026-07-08T16:36:03Z","upstream":["CVE-2026-3145","CVE-2026-3146","CVE-2026-3147","CVE-2026-6491"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0237.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35747"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IUA7WKE4WATNPXAAALXHMSPAD2GJ2CHS/"}],"affected":[{"package":{"name":"vips","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/vips?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.18.3-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0237.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}