Out-of-bounds Write Affecting sail package, versions <0.9.10-2


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.33% (25th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-SAIL-16104338
  • published18 Apr 2026
  • disclosed18 Apr 2026

Introduced: 18 Apr 2026

CVE-2026-40492  (opens in a new tab)
CWE-787  (opens in a new tab)

How to fix?

Upgrade Debian:unstable sail to version 0.9.10-2 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream sail package and not the sail package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02, the XWD codec resolves pixel format based on pixmap_depth but the byte-swap code uses bits_per_pixel independently. When pixmap_depth=8 (BPP8_INDEXED, 1 byte/pixel buffer) but bits_per_pixel=32, the byte-swap loop accesses memory as uint32_t*, reading/writing 4x the allocated buffer size. This is a different vulnerability from the previously reported GHSA-3g38-x2pj-mv55 (CVE-2026-27168), which addressed bytes_per_line validation. Commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02 contains a patch.