CVE-2026-10758
Received Received - Intake

Heap-based Out-of-Bounds Write in Esri LERC

Vulnerability report for CVE-2026-10758, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: Environmental Systems Research Institute, Inc.

Description

Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1.0 and earlier may allow a remote, unauthenticated attacker who can pass specifically crafted attacker controlled imagery to an application that uses LERC to crash the application, leading to a denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
esri lerc to 4.1.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Heap-based Out-of-Bounds Write vulnerability caused by an Integer Overflow in Esri LERC versions 4.1.0 and earlier. It occurs when a remote, unauthenticated attacker sends specially crafted imagery to an application using LERC, potentially causing the application to crash and leading to a denial of service.

Detection Guidance

Detection of this vulnerability requires checking for the use of vulnerable versions of Esri LERC (4.1.0 or earlier). Inspect applications or systems using LERC for version numbers. No specific commands are provided in the context to detect active exploitation or vulnerable installations.

Impact Analysis

If you use an application that relies on LERC versions 4.1.0 or earlier, an attacker could exploit this flaw to crash the application, disrupting service and causing a denial of service. This could affect availability of services dependent on LERC for image processing.

Compliance Impact

This vulnerability may lead to denial of service due to application crashes, which could disrupt data processing or availability. For GDPR, this could impact data integrity and availability requirements under Article 32. For HIPAA, it may affect the availability of protected health information, potentially violating Security Rule standards.

Mitigation Strategies

Update LERC to the latest version that fixes the Heap based Out-of-Bounds Write vulnerability. If updating is not possible, restrict access to applications using LERC to trusted sources only to prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10758. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart