VU#936962: Multiple file parsing vulnerabilities in FastStone Image Viewer 8.3.0.0
2026-06-22T20:52:14Z•432d2db11f936db5cf4274aab460354a365463a03445229d8ae584906e6e5704
BYOVDDBX revocationIOCTLNULL pointer dereferenceSecure Boot bypassTLSUEFIX.509 NameConstraintsautomatic thumbnailingcertificate validationchrome extensiondenial-of-servicefirmware securityheap-based buffer overflowimage parsingimproper access controlinsecure HTTPinteger overflowkernel driverman-in-the-middlephysical accessremote code executionsupply chainweak cryptography
What happened
This document aggregates multiple vulnerability advisories (June 2026) affecting desktop applications, firmware/UEFI components, kernel drivers, TLS libraries, and a Chrome extension. Notable issues include a critical heap-based buffer overflow in FastStone Image Viewer JP2 parsing that can yield remote code execution (and triggers during automatic thumbnail generation), an integer overflow in FastStone PSD parsing, improper access control and unsafe IOCTL handling in the SignalRGB kernel driver enabling local privileged access and DoS, failure to enforce X.509 NameConstraints in the Haskell '
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 432d2db11f936db5cf4274aab460354a365463a03445229d8ae584906e6e5704
- Enrichment time
- 2026-06-22T20:52:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.