cbcvebase.
CVE-2025-22423
published 2025-09-02

CVE-2025-22423: In ParseTag of dng_ifd.cpp, there is a possible way to crash the image renderer due to a missing bounds check. This could lead to remote denial of service with…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
In ParseTag of dng_ifd.cpp, there is a possible way to crash the image renderer due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected

11 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
platformexternal_dng_sdk>= 13:0 < 13:2025-04-0113:2025-04-01
platformexternal_dng_sdk>= 14:0 < 14:2025-04-0114:2025-04-01
platformexternal_dng_sdk>= 15-next:0 < 15-next:2025-04-0115-next:2025-04-01
platformexternal_dng_sdk>= 15:0 < 15:2025-04-0115:2025-04-01