Xfig: xfig: stack-overflow allows possible code execution via local input manipulation
Description
A stack-overflow in xfig's bezier_spline function allows local code execution via crafted FIG input.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A stack-overflow in xfig's bezier_spline function allows local code execution via crafted FIG input.
Vulnerability
A stack-overflow vulnerability exists in the bezier_spline function of xfig. An attacker can trigger the overflow by providing a specially crafted FIG file. The issue affects xfig versions prior to the fix released in the transfig update. The flaw is present in the xfig utility as shipped in Red Hat Enterprise Linux 9.4 and 9.6 Extended Update Support [1][3][4].
Exploitation
An attacker must have local access to the system and be able to trick a user or automated process into opening a malicious FIG file with xfig. No additional authentication is required beyond local login. The attack sequence involves crafting a FIG file with malformed coordinates or control points that cause the bezier_spline function to overflow the stack when processing the Bezier spline data [1].
Impact
Successful exploitation leads to code execution on the victim's machine. The attacker gains the ability to run arbitrary code with the privileges of the user running xfig. The vulnerability is rated Moderate severity by Red Hat, with a CVSS base score available in the referenced advisory [1][3][4].
Mitigation
The vulnerability is fixed in transfig updates released on 2026-01-15 (RHSA-2026:0704 for RHEL 9.6 and RHSA-2026:0705 for RHEL 9.4 Extended Update Support) [2][3][4]. Users should apply the latest transfig package updates from Red Hat. No workarounds are documented; the only mitigation is to update to the patched version.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
15- osv-coords14 versionspkg:deb/ubuntu/fig2dev@1:3.2.6a-6ubuntu1.1?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/fig2dev@1:3.2.7a-7ubuntu0.1?arch=source&distro=focalpkg:deb/ubuntu/fig2dev@1:3.2.8b-1?arch=source&distro=jammypkg:deb/ubuntu/fig2dev@1:3.2.9-3build2?arch=source&distro=noblepkg:deb/ubuntu/fig2dev@1:3.2.9-4?arch=source&distro=oracularpkg:deb/ubuntu/fig2dev@1:3.2.9a-3?arch=source&distro=pluckypkg:rpm/almalinux/transfigpkg:rpm/opensuse/transfig&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/transfig&distro=openSUSE%20Tumbleweedpkg:rpm/suse/transfig&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/transfig&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7pkg:rpm/suse/transfig&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/transfig&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP6pkg:rpm/suse/transfig&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP7
>= 0+ 13 more
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: < 1:3.2.7b-11.el9_7
- (no CPE)range: < 3.2.9a-150600.3.5.1
- (no CPE)range: < 3.2.9a-3.1
- (no CPE)range: < 3.2.9a-150600.3.5.1
- (no CPE)range: < 3.2.9a-150600.3.5.1
- (no CPE)range: < 3.2.8b-2.26.1
- (no CPE)range: < 3.2.9a-150600.3.5.1
- (no CPE)range: < 3.2.9a-150600.3.5.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- access.redhat.com/errata/RHSA-2026:0700mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:0704mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:0705mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2026:0756mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/security/cve/CVE-2025-46397mitrevdb-entryx_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgimitreissue-trackingx_refsource_REDHAT
- sourceforge.net/p/mcj/tickets/192/mitre
News mentions
0No linked articles in our index yet.