CVE-2026-3146 | libvips up to 8.18.0 matrixload.c vips_foreign_load_matrix_header null pointer dereference (Issue 4875 / Nessus ID 299986)
A vulnerability has been found in libvips up to 8.18.0 and classified as problematic. The impacted element is the function vips_foreign_load_matrix_header of the file libvips/foreign/matrixload.c. The manipulation leads to null pointer dereference.
This vulnerability is documented as CVE-2026-3146. The attack needs to be performed locally. There is not any exploit available.
To fix this issue, it is recommended to deploy a patch.