CVE-2016-4024: Debian Linux

Critical severity, CVSS 9.8. EPSS: 5.5% chance of exploitation in the next 30 days.

Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimensions in an image, which triggers an out-of-bounds heap memory write operation.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Enlightenment IMLIB2: up to and including 1.4.8
  • Opensuse Opensuse: version 13.2 only

Published 2016-05-13. Last modified 2026-06-17.