Skip to content
Threat Feed
low advisory

Heap-based Out-of-Bounds Write in Esri LERC

A heap-based out-of-bounds write vulnerability in Esri LERC versions 4.1.0 and earlier allows remote, unauthenticated attackers to cause a denial of service via crafted imagery.

CVE search metadata

CVE search record: CVE-2026-10758. Severity: high. CVSS: 7.5. KEV: no. Product: LERC (<= 4.1.0). Brief: Heap-based Out-of-Bounds Write in Esri LERC. Brief link: https://feed.craftedsignal.io/briefs/2026-09-esri-lerc-overflow/

The Esri LERC (Limited Error Raster Compression) library, used for rapid encoding and decoding of image data, contains a heap-based out-of-bounds write vulnerability tracked as CVE-2026-10758. The flaw originates from an integer overflow during the processing of image data. An unauthenticated, remote attacker can exploit this by providing a specifically crafted image file to an application that utilizes an affected version of the LERC library (4.1.0 and earlier). Successful exploitation leads to an application crash, resulting in a denial of service. Because LERC is integrated into various geospatial and mapping applications to handle pixel data, this vulnerability impacts any downstream software relying on vulnerable versions for image decoding.

Impact

The vulnerability poses a denial-of-service risk to applications integrating the LERC library. In environments where these applications are mission-critical for geospatial analysis or infrastructure monitoring, an exploitation event can lead to significant service degradation and operational downtime.

Recommendation

  • Identify all internal and vendor-supplied applications that include the LERC library as a dependency.
  • Upgrade instances of the LERC library to version 4.1.1 or later to remediate CVE-2026-10758.
  • Monitor application logs for abnormal crashes or process terminations associated with the ingestion of external image or raster data.

Mitigations

Upgrade LERC library to version 4.1.1 or later

immediate IT Operations

CVE-2026-10758