Heap-based Buffer Overflow Affecting vips package, versions <8.18.0-1ubuntu0.1~esm1


Severity

Recommended
0.0
medium
0
10

Based on Ubuntu security rating.

Threat Intelligence

EPSS
0.28% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU2604-VIPS-16227966
  • published13 Sept 2026
  • disclosed7 Apr 2025

Introduced: 7 Apr 2025

CVE-2025-29769  (opens in a new tab)
CWE-122  (opens in a new tab)

How to fix?

Upgrade Ubuntu:26.04 vips to version 8.18.0-1ubuntu0.1~esm1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream vips package and not the vips package as distributed by Ubuntu. See How to fix? for Ubuntu:26.04 relevant fixed versions and status.

libvips is a demand-driven, horizontally threaded image processing library. The heifsave operation could incorrectly determine the presence of an alpha channel in an input when it was not possible to determine the colour interpretation, known internally within libvips as "multiband". There aren't many ways to create a "multiband" input, but it is possible with a well-crafted TIFF image. If a "multiband" TIFF input image had 4 channels and HEIF-based output was requested, this led to libvips creating a 3 channel HEIF image without an alpha channel but then attempting to write 4 channels of data. This caused a heap buffer overflow, which could crash the process. This vulnerability is fixed in 8.16.1.

CVSS Base Scores

version 3.1