CVE-2026-42046Patch

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas import functionality allows an attacker to cause a controlled heap out-of-bounds write (heap overflow) by supplying a crafted file in the "caca" format. Depending on the build configuration and memory allocator, this may lead to memory corruption or remote code execution. This is the same vulnerability as CVE-2021-3410 but the fix at that time was not fully correct. Commit fb77acff9ba6bb01d53940da34fb10f20b156a23 fixes this vulnerability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-190CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-11); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-11: 1Mentions · 2026-05-12: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-12: 105-1105-12
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-111
Patch1
2026-05-121
Disclosure1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42046 Integer Overflow Heap Buffer Overflow in libcaca 0.99.beta20 and Earlier https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42046

    Post summary

    It announces CVE‑2026‑42046 as an integer overflow causing a heap buffer overflow in libcaca prior to 0.99.beta20, but offers no PoC, exploit, or patch details.

    0000055
    4.0K followersView on X
  • Entity@0x2ed3bb60
    Patch

    CVE-2026-42046: libcaca ≤0.99.beta20 integer overflow, heap write, RCE. Prior CVE-2021-3410 fix incomplete. Entity detects exposure. Patch: fb77acff9ba6bb01d53940da34fb10f20b156a23 https://0x2ed3bb60.xyz/threat/38bd6c3f2eacb741

    Post summary

    CVE‑2026‑42046 is a libcaca integer overflow that allows remote code execution; a patch commit is available, indicating remediation has been addressed.

    0000035
    7 followersView on X

Explore more