CVE-2026-33328
Description
libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the `gifload` operation could incorrectly determine dimensions leading to an integer overflow. This has been patched in version 8.18.1.
How to fix CVE-2026-33328
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/vips—no fix listed
Is CVE-2026-33328 being exploited?
No exploitation signal available. Neither CISA KEV nor a current EPSS score has been published for CVE-2026-33328.
Affected packages (1)
- from 0