CVE-2025-46333

z2d is a pure Zig 2D graphics library. In version 0.6.0, when writing from one surface to another using `z2d.compositor.StrideCompositor.run`, the source surface can be completely out-of-bounds on the x-axis (but not on the y-axis) by way of a negative offset. This results in an overflow of the value controlling the length of the stride. In non-safe optimization modes (consumers compiling with `ReleaseFast` or `ReleaseSmall`), this could potentially lead to invalid memory accesses or corruption. This issue is patched in version 0.6.1.
CVSS

No CVSS.

Configurations

No configuration.

History

25 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-25 21:15

Updated : 2025-04-25 21:15


NVD link : CVE-2025-46333

Mitre link : CVE-2025-46333

CVE.ORG link : CVE-2025-46333


JSON object : View

Products Affected

No product.

CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-122

Heap-based Buffer Overflow

CWE-190

Integer Overflow or Wraparound