CVE-2026-33021Disclosure(saitoha / libsixel)

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch saitoha libsixel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-after-free vulnerability in sixel_encoder_encode_bytes() because sixel_frame_init() stores the caller-owned pixel buffer pointer directly in frame->pixels without making a defensive copy. When a resize operation is triggered, sixel_frame_convert_to_rgb888() unconditionally frees this caller-owned buffer and replaces it with a new internal allocation, leaving the caller with a dangling pointer. Any subsequent access to the original buffer by the caller constitutes a use-after-free, confirmed by AddressSanitizer. An attacker who controls incoming frames can trigger this bug repeatedly and predictably, resulting in a reliable crash with potential for code execution. This issue has been fixed in version 1.8.7-r1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libsixel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-15); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
libsixel

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-15: 2Mentions · 2026-04-23: 1Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-15: 2Technical Details · 2026-04-23: 104-1504-23
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-152
Disclosure2
2026-04-231
Patch1
Full discourse3 posts
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH Severity CVE-2026-33021 CVSS 7.3 - Use-after-free in libsixel ≤1.8.7 (SIXEL encoder/decoder). Attacker-controlled frames trigger reliable crash with potential code execution. Fixed in 1.8.7-r1. #CVE #Vulnerability #PatchNow https://t.co/x8kwpnLzQO

    Post summary

    The tweet advertises a high‑severity use‑after‑free flaw (CVE-2026-33021) in libsixel, provides technical details and severity score, and notes that it is fixed in version 1.8.7‑r1.

    0000045
    26 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33021 libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-after-free vulnerability in sixel_encoder_encode… https://www.cve.org/CVERecord?id=CVE-2026-33021

    Post summary

    A brief disclosure of a use‑after‑free bug affecting libsixel up to version 1.8.7, with no indication of exploit availability, active usage, or patches.

    0000096
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33021 Use-After-Free Vulnerability in libsixel 1.8.7 and Prior Versions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33021 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A use‑after‑free vulnerability in libsixel 1.8.7 and earlier is disclosed with technical details, but no PoC, exploit, or patch information.

    0000034
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsaitohalibsixel---

Explore more