MEDIUM
CVE-2026-90596
CVSS
6.5
Description
A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be carried out remotely. Upgrading the affected component is recommended. The project was informed of the problem early through an issue report but has not responded yet.
Weakness (CWE)
CWE-189
Numeric Errors
CWE-190
Integer Overflow
EPSS Score
0.34%
Probability of exploitation in next 30 days
27.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.