Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-4738: GDAL before 3.11 allows memory corruption leading to code execution

CVE-2026-4738 · published 6 months ago
Summary

The GDAL library versions earlier than 3.11 contain a coding mistake in a component that handles compressed data. This can let an attacker cause the program to overwrite its own memory, which could crash the application or run malicious code. Upgrade GDAL to version 3.11 or later, or apply any security patches provided by your Linux distribution.

What to do
  • Update debian gdal to version 3.11.3+dfsg-1.
  • Update gdal to version 3.11.0.
Affected software
Ecosystem VendorProductAffected versions
Debian:11 debian gdal All versions
Debian:12 debian gdal All versions
Debian:13 debian gdal All versions
Debian:14 debian gdal < 3.11.3+dfsg-1
Fix: upgrade to 3.11.3+dfsg-1
Ubuntu:Pro:14.04:LTS canonical gdal All versions
Ubuntu:Pro:16.04:LTS canonical gdal All versions
Ubuntu:18.04:LTS canonical gdal All versions
Ubuntu:20.04:LTS canonical gdal All versions
Ubuntu:22.04:LTS canonical gdal All versions
Ubuntu:24.04:LTS canonical gdal All versions
Ubuntu:25.10 canonical gdal All versions
Bitnami – gdal < 3.11.0
Fix: upgrade to 3.11.0
Original advisory text
GDAL Bundled zlib (inftree9.c) Pointer Offset Optimization Undefined Behavior Allows Heap Corruption or Remote Code Execution
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/contrib/infback9 modules). This vulnerability is associated with program files inftree9.C‎. This issue affects gdal: before 3.11.0.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.9 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-119Buffer Overflow
Timeline
Published24 Mar 2026
Updated1 Oct 2026
First seen24 Mar 2026
Track software like this
Free during beta