In libavif before 1.3.0, avifImageRGBToYUV in reformat.c has integer overflows in multiplications involving rgbRowBytes, yRowBytes, uRowBytes, and vRowBytes.
References
Link | Resource |
---|---|
https://github.com/AOMediaCodec/libavif/commit/64d956ed5a602f78cebf29da023280944ee92efd | Patch |
https://github.com/AOMediaCodec/libavif/pull/2769 | Exploit Issue Tracking Patch |
https://github.com/AOMediaCodec/libavif/security/advisories/GHSA-762c-2538-h844 | Broken Link |
Configurations
History
27 Jun 2025, 15:21
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-16 05:15
Updated : 2025-06-27 15:21
NVD link : CVE-2025-48175
Mitre link : CVE-2025-48175
CVE.ORG link : CVE-2025-48175
JSON object : View
Products Affected
aomedia
- libavif
CWE
CWE-190
Integer Overflow or Wraparound