Exploitation observed; activity peaked at 3 mentions and remains active
Immediate actions
Patch affected systems immediately
Assume compromise if assets are exposed
Recommended action window: Immediate (within 24h)
NVD description
SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit c930284445ea3ff94451ccd7a57c999eca3bc979, the PSD codec computes bytes-per-pixel (`bpp`) from raw header fields `channels * depth`, but the pixel buffer is allocated based on the resolved pixel format. For LAB mode with `channels=3, depth=16`, `bpp = (3*16+7)/8 = 6`, but the format `BPP40_CIE_LAB` allocates only 5 bytes per pixel. Every pixel write overshoots, causing a deterministic heap buffer overflow on every row. Commit c930284445ea3ff94451ccd7a57c999eca3bc979 contains a patch.
Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs·
Disclosure
CVE-2026-40493 is a critical heap buffer overflow in SAIL’s PSD codec. A crafted LAB/16-bit PSD can trigger memory corruption and possible RCE.
Assessment: Tier 2 — mitigate and patch.
Full assessment: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-04-19/TIER_2_CVE-2026-40493.md
#CVE#CyberSecurity#AppSec
Post summary
The tweet announces CVE‑2026‑40493—a critical heap buffer overflow in SAIL’s PSD codec, provides a brief technical overview, and directs readers to a detailed assessment recommending mitigation and patching.
🔒 CVE-2026-40493 — SAIL’s PSD codec has a deterministic heap buffer overflow that can trigger during image parsing. If you ship or depend on affected Linux packages, verify the fix path now. Source: https://security-tracker.debian.org/tracker/CVE-2026-40493
Post summary
CVE‑2026‑40493 is a deterministic heap buffer overflow in a Linux PSD codec, and a patch or fix path is available for affected packages.
🚨 CVE-2026-40493: SAIL has heap buffer overflow in...
Math kills: PSD decoder miscalculates LAB 16-bit bpp as 6 bytes but allocates 5, triggering deterministic heap overflow...
https://zerodaysignal.com/vulnerability/CVE-2026-40493
#netsec#vulnerability#CVE#sysadmin#zeroday
Post summary
The tweet discloses a deterministic heap buffer overflow in the SAIL PSD decoder caused by a miscalculated LAB 16‑bit bpp. No PoC, exploit, or mitigation information is provided.
🚨 Critical CVEs Today: Image codecs and library pipelines (CVSS 9.1-9.8)
Affected: SAIL; NovumOS; Hot Chocolate
Internet-facing exposure dominates, led by image codecs and runtime libraries; fixes and mitigations below.
• CVE-2026-40492 (CVSS 9.8) In SAIL, the XWD codec can read/write beyond the allocated buffer when pixmap_depth is 8 and bits_per_pixel is 32, prior to patch 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02; patched in commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02.
• CVE-2026-40493 (CVSS 9.8) In SAIL, the PSD codec computes bytes-per-pixel from channels and depth but allocates the buffer differently, causing a heap overflow in LAB mode (channels=3, depth=16); patched in commit c930284445ea3ff94451ccd7a57c999eca3bc979.
• CVE-2026-40494 (CVSS 9.8) In SAIL, the TGA codec's raw-packet path lacks an equivalent bounds check, allowing writes past the end of a heap buffer; patched in commit 45d48d1f2e8e0d73e80bc1fd5310cb57f4547302.
• CVE-2026-40317 (CVSS 9.3) NovumOS allows JumpToUser to transfer control to kernel addresses from user space in versions prior to 0.24; fixed in 0.24.
• CVE-2026-40324 (CVSS 9.1) Hot Chocolate Utf8GraphQLParser has no recursion depth limit, enabling deeply nested payloads to trigger stack overflow; MaxAllowedRecursionDepth added and enforced across recursive parser methods, with fixes in 12.22.7, 13.9.16, 14.3.1, and 15.1.14.
🛠️ Action
• Patch/upgrade to the fixed versions called out (or vendor advisory latest)
• Prioritize internet-facing instances and edge appliances first
• If "no fix yet", apply the stated mitigations and reduce exposure (disable feature/module, restrict access)
• Add detections for the exploitation patterns implied by the CVEs (memory corruption paths, file-write paths, auth anomalies)
• Hunt for indicators around the affected services during the disclosure-to-now window (logs, EDR, WAF)
• Validate remediation (version checks, config verification) and monitor for reversion
Post summary
The post lists several critical image codec and library CVEs with precise technical details, highlights the required patches and mitigations, and urges immediate remediation and detection.
CVE-2026-40493 SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit c930284445ea3ff94451ccd7a57c999… https://www.cve.org/CVERecord?id=CVE-2026-40493
Post summary
The post merely mentions the CVE and a commit hash without providing evidence for exploitation, mitigation, or technical details.
🚨 CRITICAL — CVE-2026-40493
SAIL is a cross-platform library for loading and saving ima…
CVSS 9.8
⚡ Exploit in the wild 🔴 No patch yet
Full analysis → https://sec.kaitan.id/cves/CVE-2026-40493
#Meta#CyberSecurity#InfoSec
Post summary
The post announces CVE‑2026‑40493 as critical, reports that it is being exploited in the wild, and notes no patch is available.