CVE-2026-33020Disclosure(saitoha / libsixel)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch saitoha libsixel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow which leads to a heap buffer overflow via sixel_frame_convert_to_rgb888() in frame.c, where allocation size and pointer offset computations for palettised images (PAL1, PAL2, PAL4) are performed using int arithmetic before casting to size_t. For images whose pixel count exceeds INT_MAX / 4, the overflow produces an undersized heap allocation for the conversion buffer and a negative pointer offset for the normalization sub-buffer, after which sixel_helper_normalize_pixelformat() writes the full image data starting from the invalid pointer, causing massive heap corruption confirmed by ASAN. An attacker providing a specially crafted large palettised PNG can corrupt the heap of the victim process, resulting in a reliable crash and potential arbitrary code execution. This issue has been fixed in version 1.8.7-r1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-190

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libsixel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-15); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
libsixel

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-15: 2Mentions · 2026-07-31: 1Patch / Workaround · 2026-07-31: 1Technical Details · 2026-04-15: 2Technical Details · 2026-07-31: 104-1507-31
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-152
Disclosure2
2026-07-311
Patch1
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-33020 (CVSS 7.1) libsixel ≤1.8.7 - Integer overflow → heap buffer overflow via crafted PNG. Potential RCE. ✅ Fixed in 1.8.7-r1 #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/BeXwrKYhBJ

    Post summary

    The tweet announces CVE‑2026‑33020, detailing an integer overflow in libsixel that can lead to RCE, and confirms that the issue is fixed in version 1.8.7‑r1, with no evidence of active exploitation or PoC.

    0000060
    99 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33020 libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow which leads to a heap buffer overf… https://www.cve.org/CVERecord?id=CVE-2026-33020

    Post summary

    The post announces CVE‑2026‑33020, an integer overflow in libsixel (v1.8.7 and earlier) that causes a heap buffer overflow.

    0000088
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33020 Integer Overflow and Heap Buffer Overflow in libsixel Versions 1.8.7 and Prior https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33020

    Post summary

    Issues a disclosure of integer and heap buffer overflow vulnerabilities affecting libsixel versions up to 1.8.7, with no further exploit or patch details.

    0000049
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsaitohalibsixel---

Explore more