Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-4738: GDAL before 3.11 allows memory corruption leading to code execution
CVE-2026-4738 · published 6 months ago
Summary
The GDAL library versions earlier than 3.11 contain a coding mistake in a component that handles compressed data. This can let an attacker cause the program to overwrite its own memory, which could crash the application or run malicious code. Upgrade GDAL to version 3.11 or later, or apply any security patches provided by your Linux distribution.
What to do
- Update debian gdal to version 3.11.3+dfsg-1.
- Update gdal to version 3.11.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:11 | debian | gdal | All versions |
| Debian:12 | debian | gdal | All versions |
| Debian:13 | debian | gdal | All versions |
| Debian:14 | debian | gdal |
< 3.11.3+dfsg-1 Fix: upgrade to 3.11.3+dfsg-1
|
| Ubuntu:Pro:14.04:LTS | canonical | gdal | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | gdal | All versions |
| Ubuntu:18.04:LTS | canonical | gdal | All versions |
| Ubuntu:20.04:LTS | canonical | gdal | All versions |
| Ubuntu:22.04:LTS | canonical | gdal | All versions |
| Ubuntu:24.04:LTS | canonical | gdal | All versions |
| Ubuntu:25.10 | canonical | gdal | All versions |
| Bitnami | – | gdal |
< 3.11.0 Fix: upgrade to 3.11.0
|
Original advisory text
GDAL Bundled zlib (inftree9.c) Pointer Offset Optimization Undefined Behavior Allows Heap Corruption or Remote Code Execution
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/contrib/infback9 modules). This vulnerability is associated with program files inftree9.C. This issue affects gdal: before 3.11.0.
References
- https://security-tracker.debian.org/tracker/CVE-2026-4738 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-4738 Third Party Advisory
- https://ubuntu.com/security/CVE-2026-4738 Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4738.j... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-4738 URL
- https://github.com/OSGeo/gdal/pull/12244 Third Party Advisory
- https://github.com/OSGeo/gdal Product
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-119Buffer Overflow
Timeline
Published24 Mar 2026
Updated1 Oct 2026
First seen24 Mar 2026
Sources
CVE-2026-4738 · NVD
DEBIAN-CVE-2026-4738 · OSV
UBUNTU-CVE-2026-4738 · OSV
CVE-2026-4738 · OSV
BIT-gdal-2026-4738 · OSV
Track software like this
Free during beta