Unrated severityNVD Advisory· Published Aug 25, 2025· Updated Nov 3, 2025
CVE-2025-32468
CVE-2025-32468
Description
A memory corruption vulnerability exists in the BMPv3 Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .bmp file, an integer overflow can be made to occur when calculating the stride for decoding. Afterwards, this will cause a heap-based buffer to overflow when decoding the image which can lead to remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability.
Affected products
2- Range: = 0.9.8
- SAIL Image Decoding Library/SAIL Image Decoding Libraryv5Range: v0.9.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.