CVE-2019-11926

CRITICAL

GD <4.30.9 - Memory Corruption

Title source: llm
STIX 2.1

Description

Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memory via a maliciously constructed invalid JPEG input. This issue affects HHVM versions prior to 3.30.9, all versions between 4.0.0 and 4.8.3, all versions between 4.9.0 and 4.15.2, and versions 4.16.0 to 4.16.3, 4.17.0 to 4.17.2, 4.18.0 to 4.18.1, 4.19.0, 4.20.0 to 4.20.1.

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.0097
EPSS Percentile 76.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119 CWE-125
Status published
Products (2)
facebook/hhvm 4.19.0
facebook/hhvm < 3.30.9
Published Sep 06, 2019
Tracked Since Feb 18, 2026