CVE-2026-33021
Description
A flaw was found in libsixel, a SIXEL encoder/decoder implementation. An attacker who controls incoming frames can exploit a use-after-free vulnerability. This occurs because a caller-owned pixel buffer is prematurely freed during a resize operation, leaving a dangling pointer. This can lead to a reliable crash and has the potential for arbitrary code execution.
Statement
This is an Important use-after-free vulnerability in libsixel, a SIXEL encoder/decoder library. The flaw allows an attacker to trigger a reliable crash and potentially execute arbitrary code by providing specially crafted incoming frames. Red Hat products that process untrusted SIXEL image data using libsixel are susceptible to this issue.
Mitigation
To mitigate this issue, applications that utilize libsixel for processing SIXEL image data should avoid handling untrusted or unverified input. Implementing sandboxing mechanisms for applications that use libsixel can further restrict the potential impact of successful exploitation. If the vulnerable component is part of a service, a restart or service reload may be required for any configuration changes to take effect.
Understanding the Weakness (CWE)
Confidentiality
Technical Impact: Read Memory
If the expired pointer is used in a read operation, an attacker might be able to control data read in by the application.
Availability
Technical Impact: DoS: Crash, Exit, or Restart
If the expired pointer references a memory location that is not accessible to the product, or points to a location that is "malformed" (such as NULL) or larger than expected by a read or write operation, then a crash may occur.
Integrity,Confidentiality,Availability
Technical Impact: Execute Unauthorized Code or Commands
If the expired pointer is used in a function call, or points to unexpected data in a write operation, then code execution may be possible.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.