CVE-2026-8088

Name
CVE-2026-8088
Description
A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the file frmts/hdf4/hdf-eos/GDapi.c. Executing a manipulation can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.13.0RC1 is sufficient to fix this issue. This patch is called a791f70f8eaec540974ec989ca6fb00266b7646c. The affected component should be upgraded.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Product https://github.com/OSGeo/gdal/
Patch https://github.com/OSGeo/gdal/commit/a791f70f8eaec540974ec989ca6fb00266b7646c
Exploit https://github.com/OSGeo/gdal/issues/14379
Release Notes https://github.com/OSGeo/gdal/releases/tag/v3.13.0RC1
Exploit https://github.com/biniamf/pocs/tree/main/gdal-gdapi-gdfinfo-dimlist-oob-read
Exploit https://vuldb.com/submit/808040
Third Party Advisory https://vuldb.com/vuln/361841
Permissions Required https://vuldb.com/vuln/361841/cti

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:osgeo:gdal:*:*:*:*:*:*:*:* gdal >= None <= 3.12.4
cpe:2.3:a:osgeo:gdal:3.13.0:beta1:*:*:*:*:*:* gdal == None == 3.13.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
gdal edge-community 3.13.0-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.13.0-r0 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.12.4-r0 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.12.3-r4 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.12.3-r3 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.12.3-r2 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.12.3-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.12.3-r0 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.12.2-r3 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.12.2-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.12.2-r0 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.12.1-r3 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.12.1-r2 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.12.1-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.12.1-r0 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.12.0-r0 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.5-r2 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.5-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.5-r0 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.4-r6 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.4-r5 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.4-r4 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.4-r3 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.4-r2 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.4-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.4-r0 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.3-r4 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.3-r3 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.3-r2 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.3-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.3-r0 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.1-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.1-r0 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.0-r4 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.0-r3 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.0-r2 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.11.0-r0 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.10.3-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.10.3-r0 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.10.2-r2 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.10.2-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.10.2-r0 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.10.1-r3 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.10.1-r2 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.10.1-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.10.1-r0 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal edge-community 3.10.0-r7 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
gdal 3.23-community 3.11.5-r2 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable