The libwebp heap overflow: one image library, and an emergency patch across the whole industry
A heap buffer overflow in the WebP decoder, first reported as a Chrome bug and then recognised as a flaw in the library that almost everything uses to decode WebP images. CISA has it in the Known Exploited catalogue.
A fixed package version is available on 5 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.
What it actually is
The Huffman decoding in libwebp mishandles a crafted lossless WebP image and writes past the end of a heap buffer. Decoding an image is enough; nothing needs to be clicked or run.
What an attacker gets: Memory corruption in whatever process decoded the image, with a path to code execution. It was exploited in the wild against browsers.
When it applies to you, and when it does not
An old package version and a real exposure are different things. These are the conditions this one needs.
- On a server the question is what decodes uploaded images. An application that generates thumbnails, or a panel that processes user uploads, is doing exactly the affected operation on attacker-supplied data.
- It is reached through dependents rather than directly. PHP, ImageMagick, GD and Python imaging libraries all end up in libwebp.
- Restart the services after patching. A PHP-FPM pool that has been running for a month is still using the copy it loaded then.
Check your own server
ldconfig -p | grep -i webpShows whether libwebp is present and where. If nothing on the machine decodes images from untrusted sources, the practical exposure is small even when the library is installed.
Fixed package version, per distribution
From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.
| Release | Source package | State | Fixed in |
|---|---|---|---|
| Ubuntu 22.04 LTS | libwebp | Fixed | 1.2.2-2ubuntu0.22.04.2 |
| Ubuntu 24.04 LTS | libwebp | No advisory names it | no advisory for this release names it |
| Debian 12 (bookworm) | libwebp | Fixed | 1.2.4-0.2+deb12u1 |
| Debian 13 (trixie) | libwebp | Fixed | 1.2.4-0.3 |
| Rocky Linux 9 | libwebp | Fixed | 0:1.2.0-7.el9_2 |
| AlmaLinux 9 | libwebp | Fixed | 1.2.0-7.el9_2 |
Install the fix with apt update && apt upgrade on Debian and Ubuntu, or dnf update on Rocky Linux and AlmaLinux. The binaries built from libwebp are named differently on each release, so a full upgrade is the reliable way to pick this one up. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.
What SecAI has recorded about it
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
Recorded from nvd. Its weakness class is CWE-787, from NVD.
- http://www.openwall.com/lists/oss-security/2023/09/21/4
- http://www.openwall.com/lists/oss-security/2023/09/22/1
- http://www.openwall.com/lists/oss-security/2023/09/22/3
- http://www.openwall.com/lists/oss-security/2023/09/22/4
- http://www.openwall.com/lists/oss-security/2023/09/22/5
- http://www.openwall.com/lists/oss-security/2023/09/22/6
Read next
Check whether this vulnerability affects your Linux server
One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2023-4863 included. It changes nothing.