PT-2025-17936 · Z2D · Z2D

·

CVE-2025-46333

·

Published

2025-04-25

·

Updated

2025-04-26

CVSS v4.0

7.3

High

VectorAV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions z2d version 0.6.0
Description The issue arises when using z2d.compositor.StrideCompositor.run to write from one surface to another, allowing the source surface to be completely out-of-bounds on the x-axis due to a negative offset. This results in an overflow of the value controlling the length of the stride. In non-safe optimization modes, such as compiling with ReleaseFast or ReleaseSmall, this could potentially lead to invalid memory accesses or corruption.
Recommendations For version 0.6.0, update to version 0.6.1 to resolve the issue. As a temporary workaround, consider avoiding the use of negative offsets when writing from one surface to another using z2d.compositor.StrideCompositor.run until the update is applied.

Exploit

Fix

Integer Overflow

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-46333
GHSA-MM4C-P35V-7HX3

Affected Products

Z2D