parse_susp of the component Image Parser. Performing a manipulation of the argument len_id/len_des/len_src results in out-of-bounds read.This vulnerability is cataloged as CVE-2026-40026. It is possible to initiate the attack remotely. There is no exploit available.
Applying a patch is the recommended action to fix this issue.