CVE-2025-29482Classic Buffer Overflow in Libde265

Severity
6.2MEDIUMNVD
EPSS
0.1%
top 74.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 7
Latest updateJul 15

Description

Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.5 | Impact: 3.6

Affected Packages3 packages

debiandebian/libde265< libde265 1.0.7-1 (bookworm)
Debianstruktur/libde265< 1.0.7-1+3
NVDstruktur/libheif1.19.7

🔴Vulnerability Details

3
OSV
CVE-2025-29482: Buffer Overflow vulnerability in libheif 12025-04-07
CVEList
CVE-2025-29482: Buffer Overflow vulnerability in libheif 12025-04-07
GHSA
GHSA-43jx-m6w2-jq4p: Buffer Overflow vulnerability in libheif 12025-04-07

📋Vendor Advisories

2
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: DC-Specific Component (libheif) — CVE-2025-294822025-07-15
Debian
CVE-2025-29482: libde265 - Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execu...2025