CVE-2026-40492: C Bits Per Pixel Header Field Drives Wider Integer Cast
Branching on a raw parsed-header field `bits_per_pixel` to cast a pixel/scanline buffer to a wider integer type (uint16_t*/uint32_t*) is unsafe when that buffer's size/stride was derived from an independently resolved pixel format. If the header value disagrees with the resolved bits-per-pixel, the byte-swap loop will read/write past the allocated buffer (he
greprules fetch cve-2026-40492-c-bits-per-pixel-header-field-drives-wider-integer-cast --engine opengrepDescription
Branching on a raw parsed-header field `bits_per_pixel` to cast a pixel/scanline buffer to a wider integer type (uint16_t*/uint32_t*) is unsafe when that buffer's size/stride was derived from an independently resolved pixel format. If the header value disagrees with the resolved bits-per-pixel, the byte-swap loop will read/write past the allocated buffer (he
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.