PT-2025-21608 · Libavif+4 · Libavif+4

Danisjiang

·

Published

2025-04-18

·

Updated

2026-04-17

·

CVE-2025-48174

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: libavif versions prior to 1.3.0
Description: The issue is related to an integer overflow and a resultant buffer overflow in the makeRoom function within stream.c, specifically affecting stream->offset+size.
Recommendations: For versions prior to 1.3.0, update to version 1.3.0 or later to resolve the issue.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-8867
BDU:2025-11905
CVE-2025-48174
DLA-4179-1
DSA-5930-1
ECHO-E3E3-DA97-93F7
JLSEC-2026-125
MGASA-2025-0257
OPENSUSE-SU-2025:15320-1
SUSE-SU-2025:02816-1
SUSE-SU-2025:02817-1
SUSE-SU-2025:03237-1
SUSE-SU-2025_02816-1
SUSE-SU-2025_02817-1
SUSE-SU-2025_03237-1

Affected Products

Alt Linux
Astra Linux
Debian
Suse
Libavif