CVE-2026-40494: Tga Rle Raw Packet Missing Bounds Check

An RLE raw-packet decode loop writes `count` pixels (decoded from a marker byte as `(marker & 0x7F) + 1`, up to 128) into a heap output buffer without clamping `count` against the remaining buffer capacity (e.g. `pixels_num - i`). The loop advances the output pointer by `pixel_size` per iteration, which can write past the end of the destination buffer (CWE-7

Provally CuratedPublic repositoryHighHigh confidenceVerifiedApache-2.0C
greprules fetch cve-2026-40494-tga-rle-raw-packet-missing-bounds-check --engine opengrep

Description

An RLE raw-packet decode loop writes `count` pixels (decoded from a marker byte as `(marker & 0x7F) + 1`, up to 128) into a heap output buffer without clamping `count` against the remaining buffer capacity (e.g. `pixels_num - i`). The loop advances the output pointer by `pixel_size` per iteration, which can write past the end of the destination buffer (CWE-7