CVE-2026-8212
OSGeo gdal SWapi.c SWSDfldsrch heap-based overflow
5.3
MEDIUM
CVSS 3.1
EPSS 0.21%
描述
A flaw has been found in OSGeo gdal up to 3.13.0. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWapi.c. Executing a manipulation can lead to heap-based buffer overflow. The attack requires local access. The exploit has been published and may be used. Upgrading to version 3.13.0 addresses this issue. This patch is called 3e04c0385630e4d42517046d9a4967dfccfeb7fd. The affected component should be upgraded.
如何修補 CVE-2026-8212
要修補 CVE-2026-8212,請將受影響套件升級到下列已修補版本。
- —升級至 3.13.0 或更新版本
- —未列出修補版本
- —升級至 3.13.0RC1 或更新版本
- —未列出修補版本
CVE-2026-8212 正在被利用嗎?
低 — EPSS 為 0.2%,目前沒有觀察到大規模利用活動。
受影響套件(4)
- from 0, < 3.13.0
- from 0
- from 0, < 3.13.0RC1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P |
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |