CVE-2023-4863

The libwebp heap overflow: one image library, and an emergency patch across the whole industry

A heap buffer overflow in the WebP decoder, first reported as a Chrome bug and then recognised as a flaw in the library that almost everything uses to decode WebP images. CISA has it in the Known Exploited catalogue.

libwebpIn CISA’s Known Exploited catalogue since 2023-09-13EPSS 100.0% chance of an attempt in 30 daysCVSS 8.8CWE-787CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A fixed package version is available on 5 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.

One read-only command. No account, no agent, nothing changed.

What it actually is

The Huffman decoding in libwebp mishandles a crafted lossless WebP image and writes past the end of a heap buffer. Decoding an image is enough; nothing needs to be clicked or run.

What an attacker gets: Memory corruption in whatever process decoded the image, with a path to code execution. It was exploited in the wild against browsers.

When it applies to you, and when it does not

An old package version and a real exposure are different things. These are the conditions this one needs.

  • On a server the question is what decodes uploaded images. An application that generates thumbnails, or a panel that processes user uploads, is doing exactly the affected operation on attacker-supplied data.
  • It is reached through dependents rather than directly. PHP, ImageMagick, GD and Python imaging libraries all end up in libwebp.
  • Restart the services after patching. A PHP-FPM pool that has been running for a month is still using the copy it loaded then.

Check your own server

Read-only, changes nothing
ldconfig -p | grep -i webp

Shows whether libwebp is present and where. If nothing on the machine decodes images from untrusted sources, the practical exposure is small even when the library is installed.

Fixed package version, per distribution

From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.

ReleaseSource packageStateFixed in
Ubuntu 22.04 LTSlibwebpFixed1.2.2-2ubuntu0.22.04.2
Ubuntu 24.04 LTSlibwebpNo advisory names itno advisory for this release names it
Debian 12 (bookworm)libwebpFixed1.2.4-0.2+deb12u1
Debian 13 (trixie)libwebpFixed1.2.4-0.3
Rocky Linux 9libwebpFixed0:1.2.0-7.el9_2
AlmaLinux 9libwebpFixed1.2.0-7.el9_2

Install the fix with apt update && apt upgrade on Debian and Ubuntu, or dnf update on Rocky Linux and AlmaLinux. The binaries built from libwebp are named differently on each release, so a full upgrade is the reliable way to pick this one up. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.

What SecAI has recorded about it

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

Recorded from nvd. Its weakness class is CWE-787, from NVD.

Read next

Check whether this vulnerability affects your Linux server

One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2023-4863 included. It changes nothing.