CVE-2021-40812

Updated: 2026-02-27 01:29:07.929409

Description:

The GD Graphics Library (aka LibGD) through 2.3.2 has an out-of-bounds read because of the lack of certain gdGetBuf and gdPutBuf return value checks.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 4.3
CVSS Version 3.x MEDIUM 6.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 6 ELS gd 2.0.35 6.5 MEDIUM Not Vulnerable 2021-11-02 14:03:16 CVE-2021-40812 is only reachable in LibGD’s BMP/WebP encoding paths that use the gdIOCtx I/O callb...
CentOS 8.4 ELS gd 2.2.5 6.5 MEDIUM Ignored 2022-02-03 14:47:48 Ignored due to low severity
CentOS 8.5 ELS gd 2.2.5 6.5 MEDIUM Ignored 2022-02-10 08:36:20 Ignored due to low severity
CloudLinux 6 ELS gd 2.0.35 6.5 MEDIUM Not Vulnerable 2021-11-02 14:03:16
Oracle Linux 6 ELS gd 2.0.35 6.5 MEDIUM Not Vulnerable 2021-11-02 14:03:16 CVE-2021-40812 is only reachable in LibGD’s BMP/WebP encoding paths that use the gdIOCtx I/O callb...
Ubuntu 16.04 ELS gd 2.1.1 6.5 MEDIUM Released CLSA-2021:1635459219 2021-11-02 14:03:16
Ubuntu 18.04 ELS gd 2.2.5 6.5 MEDIUM Released CLSA-2023:1689009763 2023-07-10 14:07:00