---
id: CVE-2026-90593
title: A vulnerability was determined in embedded-graphics up to 0.8.2
summary: >-
  A vulnerability was determined in embedded-graphics up to 0.8.2. This affects
  the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs.
  Executing a manipulation of the argument width can lead to integer overflow.
  The atta…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-189
  - CWE-190
product: embedded-graphics
affected:
  - embedded-graphics 0.8.0
  - embedded-graphics 0.8.1
  - embedded-graphics 0.8.2
published: '2026-09-13'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T15:18:32.180'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90593'
references:
  - url: 'https://github.com/embedded-graphics/embedded-graphics/'
    label: cna@vuldb.com
  - url: 'https://github.com/embedded-graphics/embedded-graphics/issues/821'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90593'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/913787'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403175'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403175/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
epss: 0.00522
epssPercentile: 0.41792
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-16T14:15:42.824083Z'
ingestedAt: '2026-09-14T15:23:07.468Z'
---

## Overview

A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to integer overflow. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
