PT-2025-16387 · Pleezer · Pleezer

Madmarcsen

·

Published

2025-04-14

·

Updated

2025-04-15

·

CVE-2025-32439

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions pleezer versions prior to 0.16.0
Description The issue arises from hook scripts in pleezer being spawned without proper process cleanup, leading to zombie processes in the system's process table. This occurs with every track change and playback event, causing resource exhaustion over time as the system's process table fills up. The problem is worsened by rapid events, whether through normal use or potential manipulation of the Deezer Connect protocol traffic.
Recommendations For versions prior to 0.16.0, update to version 0.16.0 to resolve the issue. As a temporary workaround, consider disabling hook scripts until the update is applied. Restricting the frequency of track changes and playback state changes may also help minimize the risk of exploitation.

Exploit

Fix

Missing Release of Resource after Effective Lifetime

Weakness Enumeration

Related Identifiers

CVE-2025-32439
GHSA-472W-7W45-G3W5

Affected Products

Pleezer