CVE-2026-6491 | libvips up to 8.18.2 nip2 vips7compat.c im_minpos_vec n heap-based overflow (Issue 4965)
A vulnerability described as problematic has been identified in libvips up to 8.18.2. The affected element is the function im_minpos_vec of the file libvips/deprecated/vips7compat.c of the component nip2 Handler. Such manipulation of the argument n leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2026-6491. An attack has to be approached locally. Furthermore, there is an exploit available.
The vendor confirms that they will "be removing the deprecated area in libvips 8.19".