USN-8812-1: GDAL vulnerabilities
Ubuntu patched GDAL flaws that could allow code execution or crashes via malicious files.
Ubuntu Security Notice USN-8812-1 describes multiple GDAL vulnerabilities. CVE-2026-49014, affecting Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS, involves incorrect handling of certain netCDF files that could allow arbitrary code execution. HDF-EOS issues CVE-2026-8086, CVE-2026-8087, CVE-2026-8212, and CVE-2026-8213 may cause a crash or code execution, while CVE-2026-8084 and CVE-2026-8088 can crash GDAL through crafted metadata. The notice does not say these flaws are being exploited.
- CVE-2026-49014 may allow code execution via netCDF files on three Ubuntu LTS releases.
- Four HDF-EOS flaws may crash GDAL or allow arbitrary code execution.
- Two HDF-EOS metadata bugs can cause a denial of service.
- The notice does not report exploitation in the wild.
Vulnerabilities mentionedAll →
- CVE-2026-490147.8<1%In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflowpublished · osgeo gdal
- CVE-2026-80861.9<1%A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4
It was discovered that GDAL incorrectly handled certain netCDF files. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-49014) It was discovered that GDAL incorrectly handled certain HDF-EOS files. An attacker could possibly use this issue to cause a crash or execute arbitrary code. (CVE-2026-8086, CVE-2026-8087, CVE-2026-8212, CVE-2026-8213) It was discovered that GDAL incorrectly handled certain HDF-EOS file metadata. An attacker could possibly use this issue to cause GDAL to crash, resulting in a denial of service. (CVE-2026-8084, CVE-2026-8088)
This source does not provide full text. Read it at ubuntu.com.