CVE-2026-102805 stb 图像编码整数溢出漏洞
影响攻击者可远程触发整数溢出,可能导致内存破坏或拒绝服务
Nothings stb 库(stb_image_write.h)在图像编码相关函数中存在整数溢出漏洞,影响 stbi_write_png_to_mem、stbi_write_jpg_core 和 stbi_write_tga_core 等函数。该漏洞可被远程利用,且利用代码已公开,存在被实际攻击的风险。
影响范围
受影响版本为 Nothings stb 至 1.16(含),具体受影响范围以官方公告为准。
漏洞详情
漏洞类型为整数溢出,成因是图像编码过程中对尺寸或长度等参数的计算未做充分校验,导致整型溢出。攻击者可通过构造特制的图像数据触发溢出,进而可能造成内存破坏或程序崩溃。该漏洞可远程利用,且公开的利用代码可能被直接使用。
利用条件与风险
利用前提是目标程序使用受影响版本的 stb 库处理攻击者可控的图像数据;由于利用代码已公开,实战风险较高,可能导致拒绝服务或进一步的内存破坏。
修复建议
建议关注 Nothings stb 官方更新,升级到修复该漏洞的版本;在官方修复前,可对图像编码输入进行严格校验,或避免处理不可信来源的图像数据。
A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be executed remotely. The exploit has been published and may be used.