In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterizeedges8 due to an integer overflow in pixmansamplefloor_y.
{
"license": "CC-BY-4.0",
"sources": [
{
"imported": "2026-04-22T10:49:11.533Z",
"modified": "2025-05-02T20:15:19.253Z",
"published": "2022-11-03T06:15:10.623Z",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2022-44638",
"database_specific": {
"status": "Modified"
},
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44638",
"id": "CVE-2022-44638"
}
]
}