CVE-2026-94030 | SerenityOS up to 3d83e4509fd20d7438e1ae8470ffe668c136229c LibGfx BMPLoader.cpp decode_bmp_pixel_data height integer overflow (Issue 26957)
A vulnerability marked as problematic has been reported in SerenityOS up to 3d83e4509fd20d7438e1ae8470ffe668c136229c. Affected by this vulnerability is the function decode_bmp_pixel_data of the file Userland/Libraries/LibGfx/ImageFormats/BMPLoader.cpp of the component LibGfx. The manipulation of the argument height leads to integer overflow.
This vulnerability is uniquely identified as CVE-2026-94030. The attack is possible to be carried out remotely. Moreover, an exploit is present.
This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. Applying a patch is the recommended action to fix this issue.
This was reproducible with a minimal 55-byte PoC via the standard image-decode fuzz target but evidence for an actual exploitable defect is thin.VulDB Recent EntriesRead More