📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global phishing Cross-sector HIGH 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 24m Global vulnerability IT Infrastructure CRITICAL 1h Global vulnerability Technology and Software Development HIGH 2h Global vulnerability Enterprise IT and Government CRITICAL 2h Global ransomware Multiple Sectors / Enterprise CRITICAL 3h Global general Technology and Legal MEDIUM 3h Global ransomware Financial Services / Cryptocurrency CRITICAL 4h Global general Industrial Control Systems / Operational Technology HIGH 5h Global apt Managed Service Providers (MSPs) / IT Services HIGH 6h Global phishing Cross-sector HIGH 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 24m Global vulnerability IT Infrastructure CRITICAL 1h Global vulnerability Technology and Software Development HIGH 2h Global vulnerability Enterprise IT and Government CRITICAL 2h Global ransomware Multiple Sectors / Enterprise CRITICAL 3h Global general Technology and Legal MEDIUM 3h Global ransomware Financial Services / Cryptocurrency CRITICAL 4h Global general Industrial Control Systems / Operational Technology HIGH 5h Global apt Managed Service Providers (MSPs) / IT Services HIGH 6h Global phishing Cross-sector HIGH 4h Global vulnerability Enterprise Software / ERP Systems CRITICAL 24m Global vulnerability IT Infrastructure CRITICAL 1h Global vulnerability Technology and Software Development HIGH 2h Global vulnerability Enterprise IT and Government CRITICAL 2h Global ransomware Multiple Sectors / Enterprise CRITICAL 3h Global general Technology and Legal MEDIUM 3h Global ransomware Financial Services / Cryptocurrency CRITICAL 4h Global general Industrial Control Systems / Operational Technology HIGH 5h Global apt Managed Service Providers (MSPs) / IT Services HIGH 6h
Vulnerabilities

CVE-2026-44636

High
CWE-122 — Weakness Type
Published: May 14, 2026  ·  Modified: May 21, 2026  ·  Source: NVD
CVSS v3
7.4
🔗 NVD Official
📄 Description (English)

libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, signed integer overflow in sixel_encode_highcolor's allocation size calculation can lead to a heap buffer overflow. The public sixel_encode entry point validates only that width and height are greater than zero, with no upper bound. width and height are multiplied as plain int when computing the allocation size for paletted_pixels and normalized_pixels. Any caller that asks libsixel to encode a pixel buffer with width times height greater than INT_MAX (about 2.15 billion) will hit a wrapped allocation size; under the right wrap, the malloc succeeds with a buffer much smaller than the encoder expects, and the encoder writes past the end of the heap allocation. This vulnerability is fixed in 1.8.7-r2.

🤖 AI Executive Summary

libsixel versions before 1.8.7-r2 contain a signed integer overflow in heap buffer allocation that can be exploited through the sixel_encode function with large width/height parameters. This vulnerability allows attackers to trigger heap buffer overflow by providing image dimensions exceeding INT_MAX, potentially leading to memory corruption and code execution.

📄 Description (Arabic)

يحتوي libsixel على خلل في دالة sixel_encode_highcolor حيث يتم حساب حجم التخصيص باستخدام ضرب عددين صحيحين بدون فحص الحدود العليا. عندما يكون حاصل ضرب العرض والارتفاع أكبر من INT_MAX (حوالي 2.15 مليار)، يحدث تجاوز في العدد الصحيح مما يؤدي إلى تخصيص مخزن مؤقت أصغر من المتوقع. يكتب المشفر بعد نهاية المخزن المؤقت المخصص مما يسبب تلف الذاكرة.

🤖 ملخص تنفيذي (AI)

مكتبة libsixel الإصدارات السابقة 1.8.7-r2 تحتوي على تجاوز عدد صحيح موقع في تخصيص المخزن المؤقت للكومة يمكن استغلاله من خلال دالة sixel_encode. يمكن لمهاجمين تشغيل تجاوز المخزن المؤقت للكومة بتوفير أبعاد صورة تتجاوز INT_MAX مما قد يؤدي إلى تلف الذاكرة وتنفيذ الأكواد.

🤖 AI Intelligence Analysis Analyzed: May 20, 2026 16:00
🇸🇦 Saudi Arabia Impact Assessment
Saudi Relevance: high
🏢 Affected Saudi Sectors
telecom government healthcare
🎯 MITRE ATT&CK Techniques
⚖️ Saudi Risk Score (AI)
7.0
/ 10.0
🔧 Remediation Steps (English)
Update libsixel to version 1.8.7-r2 or later immediately. Implement input validation in applications using libsixel to enforce reasonable upper bounds on image width and height parameters before passing to encoding functions. Validate that width * height does not exceed safe integer limits.
🔧 خطوات المعالجة (العربية)
قم بتحديث libsixel إلى الإصدار 1.8.7-r2 أو أحدث فوراً. طبق التحقق من صحة المدخلات في التطبيقات التي تستخدم libsixel لفرض حدود عليا معقولة على معاملات عرض وارتفاع الصورة قبل تمريرها إلى وظائف الترميز. تحقق من أن عرض × ارتفاع لا يتجاوز حدود الأعداد الصحيحة الآمنة.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.12.6.1 A.14.2.1
🔵 SAMA CSF
ID.RA-1 PR.IP-12
🟡 ISO 27001:2022
A.12.6.1 A.14.2.1 A.14.2.5
📦 Affected Products / CPE 1 entries
saitoha:libsixel
📊 CVSS Score
7.4
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorL — Low / Local
Attack ComplexityH — High
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.4
CWECWE-122
EPSS0.01%
Exploit No
Patch ✗ No
Published 2026-05-14
Source Feed nvd
🇸🇦 Saudi Risk Score
7.0
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-122
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.