CVE-2021-26826

medium
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
5.5

Description

A stack overflow issue exists in Godot Engine up to v3.2 and is caused by improper boundary checks when loading .TGA image files. Depending on the context of the application, attack vector can be local or remote, and can lead to code execution and/or system crash.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-26826

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202103-26

OS impact

OSVersionStatusFixed in
arch archfixed3.2.3-2
debian debianbookwormaffected
debian debianbullseyeaffected
debian debiansidfixed3.5.1-stable-1
debian debiantrixiefixed3.5.1-stable-1

References

Verify integrity in audit chain (admin only). AS-IS.