{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/embedded-graphics/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:embedded-graphics:embedded-graphics:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-90593"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["embedded-graphics (\u003c= 0.8.2)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","memory-corruption"],"_cs_type":"advisory","_cs_vendors":["embedded-graphics"],"content_html":"\u003cp\u003eThe embedded-graphics library, widely used in Rust-based embedded systems development, contains an integer overflow vulnerability in the ImageRaw::draw_sub_image function located in src/image/image_raw.rs. This vulnerability affects all versions up to 0.8.2. An attacker can exploit this flaw by providing a specially crafted width argument during the drawing process. This manipulation triggers an integer overflow, which can lead to memory corruption or undefined behavior within the device's memory space. Because this library is commonly used in low-level firmware and embedded display drivers, the scope of impact includes potential crashes or remote code execution depending on the specific integration within the target hardware. As of the report date, the project maintainers have not issued a patch or response to the reported vulnerability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability in embedded environments can lead to denial-of-service conditions through device crashes or arbitrary code execution. Given the library's role in rendering image data, devices handling untrusted or remote image inputs are at the highest risk of exploitation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePerform an inventory of embedded firmware builds to identify projects utilizing embedded-graphics versions 0.8.2 or older.\u003c/li\u003e\n\u003cli\u003eMonitor the official embedded-graphics repository for upcoming security advisories or patch releases addressing CVE-2026-90593.\u003c/li\u003e\n\u003cli\u003eIf a patch is unavailable, implement input validation logic to sanitize the width argument before it is passed to the ImageRaw::draw_sub_image function to prevent integer overflow conditions.\u003c/li\u003e\n\u003cli\u003eRestrict the ability of external or untrusted sources to influence rendering parameters in embedded display applications.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-13T21:27:06Z","date_published":"2026-09-13T21:27:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-13-embedded-graphics-integer-overflow/","summary":"An integer overflow vulnerability in the embedded-graphics library (up to version 0.8.2) allows remote attackers to trigger memory corruption via a manipulated width argument in ImageRaw::draw_sub_image.","title":"Integer Overflow in embedded-graphics Library","url":"https://feed.craftedsignal.io/briefs/2026-09-13-embedded-graphics-integer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Embedded-Graphics","version":"https://jsonfeed.org/version/1.1"}