mediumVulnerability

GHSA-5qv7-j6w5-fr4m

A read of pixels was coded as modifying coordinates to lie within the image bounds. It would calculate a coordinate by adding a constant to an input and taking the minimum of the resulting coordinate and 'dimension - 1'. This would not protect against malicious inputs that could overflow the addition. Following the tricked bounds check, the image could then be sampled at multiple differently calculated coordinates that exceeded the bounds.

Properties

ghsa_id
GHSA-5qv7-j6w5-fr4m
severity
medium
summary
imageproc has fragile bounds check when sampling from image
cve_id
GHSA-5qv7-j6w5-fr4m
is_ghsa_only
true
ghsa_published
2026-05-07T03:03:48Z
source_url
https://github.com/advisories/GHSA-5qv7-j6w5-fr4m
ghsa_updated
2026-05-07T03:03:51Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]rust/imageproc

AFFECTS (1)

[Software]rust/imageproc

HAS_WEAKNESS (1)

[Weakness]Integer Overflow or Wraparound

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-5qv7-j6w5-fr4m — Ninja Signal Threat Intelligence | Ninja Signal