Vips: On 32-bit systems in versions before and including 8.18.0, the gifload operation could incorrectly determine dimensions leading to an integer… (CVE-2026-33328)
A vulnerability in libvips versions up to and including 8.18.0 on 32-bit systems allows the gifload operation to incorrectly determine image dimensions, causing an integer overflow. This issue has been fixed in version 8.18.1. The vulnerability has a medium severity with a CVSS score of 5.5 and can cause denial of service due to application crashes.
AI Analysis
Technical Summary
libvips is an image processing library with low memory requirements. On 32-bit systems, versions before and including 8.18.0 contain a vulnerability in the gifload operation where incorrect dimension calculation leads to an integer overflow. This flaw can cause a denial of service by crashing the application processing GIF images. The issue is resolved in version 8.18.1.
Potential Impact
The vulnerability does not impact confidentiality or integrity but can cause availability issues by crashing applications that process GIF images using the vulnerable libvips versions on 32-bit systems. There are no known exploits in the wild.
Mitigation Recommendations
Upgrade libvips to version 8.18.1 or later to apply the official fix. No other mitigations are indicated.
Vips: On 32-bit systems in versions before and including 8.18.0, the gifload operation could incorrectly determine dimensions leading to an integer… (CVE-2026-33328)
Description
A vulnerability in libvips versions up to and including 8.18.0 on 32-bit systems allows the gifload operation to incorrectly determine image dimensions, causing an integer overflow. This issue has been fixed in version 8.18.1. The vulnerability has a medium severity with a CVSS score of 5.5 and can cause denial of service due to application crashes.
CVSS v3.1
Score 5.5medium
Affected software
pkg:deb/ubuntu/vips?arch=source&distro=esm-apps/xenialpkg:deb/ubuntu/vips?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/vips?arch=source&distro=focalpkg:deb/ubuntu/vips?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/vips?arch=source&distro=noblepkg:deb/ubuntu/vips?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
libvips is an image processing library with low memory requirements. On 32-bit systems, versions before and including 8.18.0 contain a vulnerability in the gifload operation where incorrect dimension calculation leads to an integer overflow. This flaw can cause a denial of service by crashing the application processing GIF images. The issue is resolved in version 8.18.1.
Potential Impact
The vulnerability does not impact confidentiality or integrity but can cause availability issues by crashing applications that process GIF images using the vulnerable libvips versions on 32-bit systems. There are no known exploits in the wild.
Mitigation Recommendations
Upgrade libvips to version 8.18.1 or later to apply the official fix. No other mitigations are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-33328
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a885f2bacd9273b493f8276
Added to database: 08/21/2026, 14:22:35 UTC
Last enriched: 08/21/2026, 14:39:29 UTC
Last updated: 08/21/2026, 22:52:11 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.