Ghostwire

CVE-2026-42146: CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file...

MEDIUM CVSS 5.5

Published: May 4, 2026 | Last Modified: May 4, 2026

Description

CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file header is used directly to compute an allocation size without validating it against the remaining file size. A crafted BMP file with a large nb_colors value triggers an out-of-memory condition, crashing any application that uses CImg to load untrusted BMP files. This issue has been patched via commit c3aacf5.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References