Logo
vulnerabilityCVE-2025-48174
Name
CVE-2025-48174
Source
NVD ( link)Debian ( link)
Description
In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libavif
Patched

Vulnerability Ratings#


4.5
CVSSv31
9.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.3.0
Not Affected
buildroot
master
1.4.2
Not Affected
yocto
master
1.4.1
Not Affected

Resolved with patches#


libavif (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix format errors
"Danis Jiang (Yuhao Jiang)"
CVE-2025-48174
2
Add another integer overflow check to makeRoom
Wan-Teh Chang <wtc@google.com>
CVE-2025-48174
3
Add integer overflow check to makeRoom.
DanisJiang <43723722+DanisJiang@users.noreply.github.com>
CVE-2025-48174
4
Add integer overflow checks to makeRoom.
DanisJiang <43723722+DanisJiang@users.noreply.github.com>
CVE-2025-48174