libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl_free() twice on the same pointer without triggering detection, as libc's malloc metadata overwrites babl's signature field upon freeing, enabling potential memory corruption and code execution.

Project Subscriptions

Vendors Products
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 18 May 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 17 May 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Gegl libbabl
Vendors & Products Gegl libbabl

Sat, 16 May 2026 15:45:00 +0000

Type Values Removed Values Added
Description libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl_free() twice on the same pointer without triggering detection, as libc's malloc metadata overwrites babl's signature field upon freeing, enabling potential memory corruption and code execution.
Title libbabl 0.1.62 Broken Double Free Detection Memory Safety
First Time appeared Gegl
Gegl gegl
Weaknesses CWE-415
CPEs cpe:2.3:a:gegl:gegl:0.1.62:*:*:*:*:*:*:*
Vendors & Products Gegl
Gegl gegl
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-05-18T18:09:18.610Z

Reserved: 2026-05-15T14:52:46.405Z

Link: CVE-2020-37239

cve-icon Vulnrichment

Updated: 2026-05-18T18:08:58.869Z

cve-icon NVD

Status : Deferred

Published: 2026-05-16T16:16:20.097

Modified: 2026-05-18T20:16:36.607

Link: CVE-2020-37239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-17T17:00:51Z

Weaknesses