cbcvebase.
CVE-2025-32460
published 2025-04-09

CVE-2025-32460: GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.

PriorityP339critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.34%
26.3th percentile
GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.

Affected

6 ranges
VendorProductVersion rangeFixed in
debiangraphicsmagick< graphicsmagick 1.4+really1.3.40-4+deb12u1 (bookworm)graphicsmagick 1.4+really1.3.40-4+deb12u1 (bookworm)
graphicsmagickgraphicsmagick< 8e56520435df50f618a03f2721a39a70a515f1cb8e56520435df50f618a03f2721a39a70a515f1cb
graphicsmagickgraphicsmagick< 1.3.461.3.46
graphicsmagickgraphicsmagick>= 0 < 1.4+really1.3.40-4+deb12u11.4+really1.3.40-4+deb12u1
graphicsmagickgraphicsmagick>= 0 < 1.4+really1.3.45+hg17696-11.4+really1.3.45+hg17696-1
graphicsmagickgraphicsmagick>= 0 < 1.4+really1.3.45+hg17696-11.4+really1.3.45+hg17696-1

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv9.1CRITICAL
vendor_debian4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.