CVE-2026-90596 MEDIUM

CVE-2026-90596: embedded-graphics image_raw.rs new/bytes_per_row integer overflow

Vendor N/A
Product embedded-graphics
Weakness CWE-190
Published September 13, 2026
Last update September 15, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X

What the vulnerability does

01Description

A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be carried out remotely. Upgrading the affected component is recommended. The project was informed of the problem early through an issue report but has not responded yet.

Key dates

02Disclosure timeline

September 13, 2026 CVE published
September 15, 2026 Record updated