CVE-2026-47667 PUBLISHED

CImg Library: Uncontrolled Memory Allocation and Memory Leak in `_load_analyze()` via Crafted NIfTI/Analyze Header

Assigner: GitHub_M
Reserved: 19.05.2026 Published: 21.07.2026 Updated: 21.07.2026

CImg Library is a C++ library for image processing. Prior to version 4.0.0 in _load_analyze(), the header_size field is read as an unsigned int from the first 4 bytes of an Analyze/NIfTI file and passed directly to new unsigned char[header_size] without being bounded against the actual file size. A value up to ~4 GB is accepted. If the subsequent fread returns short as it will for any malformed file), the function throws a CImgIOException and the allocated buffer is never freed. A 6-byte crafted file is sufficient to trigger an allocation of ~1.3 GB per call, with the full allocation leaked on every error path. The issue is reachable via load_analyze() and the generic load() when the file extension is .hdr, .img, or .nii. Version 4.0.0 fixes the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor GreycLab
Product CImg
Versions
  • Version < 4.0.0 is affected

References

Problem Types

  • CWE-401: Missing Release of Memory after Effective Lifetime CWE
  • CWE-789: Memory Allocation with Excessive Size Value CWE
  • CWE-1284: Improper Validation of Specified Quantity in Input CWE