CVE-2026-8084
Publication date 7 May 2026
Last updated 24 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hdf-eos/SWapi.c of the component HDF-EOS Grid File Handler. This manipulation causes out-of-bounds read. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.13.0RC1 is able to resolve this issue. Patch name: a791f70f8eaec540974ec989ca6fb00266b7646c. Upgrading the affected component is advised.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| gdal | 26.04 LTS resolute |
Fixed 3.12.2+dfsg-1ubuntu0.1~esm1
|
| 24.04 LTS noble |
Fixed 3.8.4+dfsg-3ubuntu3+esm1
|
|
| 22.04 LTS jammy |
Fixed 3.4.1+dfsg-1ubuntu0.1~esm1
|
|
| 20.04 LTS focal |
Fixed 3.0.4+dfsg-1ubuntu0.1~esm1
|
|
| 18.04 LTS bionic |
Fixed 2.2.3+dfsg-2ubuntu0.1~esm1
|
|
| 16.04 LTS xenial |
Fixed 1.11.3+dfsg-3ubuntu0.1~esm2
|
|
| 14.04 LTS trusty |
Fixed 1.10.1+dfsg-5ubuntu1+esm3
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialSeverity score breakdown
CVSS version:
Base score
1.9 · Low
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Base score
3.3 · Low
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L