CVE-2026-8088
OSGeo gdal GDapi.c GDfieldinfo out-of-bounds
5.5
MEDIUM
CVSS 3.1
EPSS 0.25%
描述
A weakness has been identified in OSGeo gdal up to 3.13.0. The affected element is the function GDfieldinfo of the file frmts/hdf4/hdf-eos/GDapi.c. Executing a manipulation can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.13.0 is sufficient to fix this issue. This patch is called a791f70f8eaec540974ec989ca6fb00266b7646c. The affected component should be upgraded.
如何修補 CVE-2026-8088
要修補 CVE-2026-8088,請將受影響套件升級到下列已修補版本。
- —升級至 3.13.0 或更新版本
CVE-2026-8088 正在被利用嗎?
低 — EPSS 為 0.2%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 3.13.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |