CVE-2026-40493: Image Codec Bpp From Raw Channels Depth

Bytes-per-pixel is computed from raw header fields ($STATE->channels * $STATE->depth) instead of from the resolved pixel format (e.g. sail_bits_per_pixel(image->pixel_format)). When the row/scan-line buffer is allocated based on the resolved pixel_format, this raw-header-derived stride can exceed the allocated bytes-per-pixel, causing heap buffer overflows o

Provally CuratedPublic repositoryHighHigh confidenceVerifiedApache-2.0C
greprules fetch cve-2026-40493-image-codec-bpp-from-raw-channels-depth --engine opengrep

Description

Bytes-per-pixel is computed from raw header fields ($STATE->channels * $STATE->depth) instead of from the resolved pixel format (e.g. sail_bits_per_pixel(image->pixel_format)). When the row/scan-line buffer is allocated based on the resolved pixel_format, this raw-header-derived stride can exceed the allocated bytes-per-pixel, causing heap buffer overflows o