🛡️ MGASA-2026-0237 — vips
Description
Updated vips packages fix security vulnerabilities
This update fixes several security issues:
A flaw has been found in libvips up to 8.18.0. The affected element is
the function
vips_foreign_load_matrix_file_is_a/vips_foreign_load_matrix_header of
the file libvips/foreign/matrixload.c. Executing a manipulation can lead
to memory corruption. The attack needs to be launched locally.
(CVE-2026-3145)
A vulnerability has been found in libvips up to 8.18.0. The impacted
element is the function vips_foreign_load_matrix_header of the file
libvips/foreign/matrixload.c. The manipulation leads to null pointer
dereference. The attack needs to be performed locally. (CVE-2026-3146)
A vulnerability was found in libvips up to 8.18.0. This affects the
function vips_foreign_load_csv_build of the file
libvips/foreign/csvload.c. The manipulation results in heap-based buffer
overflow. The attack requires a local approach. The exploit has been
made public and could be used. (CVE-2026-3147)
A security vulnerability has been detected in libvips up to 8.18.2. The
affected element is the function im_minpos_vec of the file
libvips/deprecated/vips7compat.c of the component nip2 Handler. Such
manipulation of the argument n leads to heap-based buffer overflow. An
attack has to be approached locally. The exploit has been disclosed
publicly and may be used. (CVE-2026-6491)
Affected software
MGASA-2026-0237 is recorded against 1 package.
- vips (fixed in 8.18.3-1.mga10)
Timeline and source
Published on 8 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
advisories.mageia.org (Advisory)
bugs.mageia.org (Report)
lists.fedoraproject.org (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| vips | — | 8.18.3-1.mga10 |
References
Similar Threats
- Unknown DEBIAN-CVE-2026-33327
- Unknown DEBIAN-CVE-2026-33328
- Unknown DEBIAN-CVE-2026-35590
- Unknown DEBIAN-CVE-2026-35591
- Unknown DEBIAN-CVE-2026-6491
More MGASA 2026 advisories
Browse all of MGASA 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by MGASA-2026-0237?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MGASA-2026-0237 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.