CVE-2026-33021

Description

A flaw was found in libsixel, a SIXEL encoder/decoder implementation. An attacker who controls incoming frames can exploit a use-after-free vulnerability. This occurs because a caller-owned pixel buffer is prematurely freed during a resize operation, leaving a dangling pointer. This can lead to a reliable crash and has the potential for arbitrary code execution.

Statement

This is an Important use-after-free vulnerability in libsixel, a SIXEL encoder/decoder library. The flaw allows an attacker to trigger a reliable crash and potentially execute arbitrary code by providing specially crafted incoming frames. Red Hat products that process untrusted SIXEL image data using libsixel are susceptible to this issue.

Mitigation

To mitigate this issue, applications that utilize libsixel for processing SIXEL image data should avoid handling untrusted or unverified input. Implementing sandboxing mechanisms for applications that use libsixel can further restrict the potential impact of successful exploitation. If the vulnerable component is part of a service, a restart or service reload may be required for any configuration changes to take effect.

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Memory

If the expired pointer is used in a read operation, an attacker might be able to control data read in by the application.

Availability

Technical Impact: DoS: Crash, Exit, or Restart

If the expired pointer references a memory location that is not accessible to the product, or points to a location that is "malformed" (such as NULL) or larger than expected by a read or write operation, then a crash may occur.

Integrity,Confidentiality,Availability

Technical Impact: Execute Unauthorized Code or Commands

If the expired pointer is used in a function call, or points to unexpected data in a write operation, then code execution may be possible.

Frequently Asked Questions

Want to get errata notifications? Sign up here.