CVE-2026-3282 | libvips 8.19.0 unpremultiply.c vips_unpremultiply_build alpha_band out-of-bounds (Issue 4881)
A vulnerability described as problematic has been identified in libvips 8.19.0. This vulnerability affects the function vips_unpremultiply_build of the file libvips/conversion/unpremultiply.c. Executing a manipulation of the argument alpha_band can lead to out-of-bounds read.
This vulnerability is registered as CVE-2026-3282. The attack needs to be launched locally. Furthermore, an exploit is available.
A patch should be applied to remediate this issue.