Logo
vulnerabilityCVE-2025-6199
Name
CVE-2025-6199
Source
NVD ( link)Debian ( link)
Description
A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
gdk-pixbuf
Patched

Vulnerability Ratings#


3.3
CVSSv31
3.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.42.12
Not Affected
buildroot
master
2.42.12
Not Affected
openwrt
master
2.44.6-r1
Not Affected
openwrt
openwrt-25.12
2.42.12-r1
Not Affected
yocto
kirkstone
2.42.10
Patched
yocto
master
2.44.6
Not Affected

Resolved with patches#


gdk-pixbuf (yocto:kirkstone)

#
Title
Author
Resolve
1
lzw: Fix reporting of bytes written in decoder
lumi <lumi@suwi.moe>
CVE-2025-6199

gdk-pixbuf (yocto:scarthgap)

#
Title
Author
Resolve
1
lzw: Fix reporting of bytes written in decoder
lumi <lumi@suwi.moe>
CVE-2025-6199