CVE-2025-48174 — Integer Overflow or Wraparound in Libavif
Severity
9.1CRITICALNVD
EPSS
0.4%
top 41.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 16
Description
In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HExploitability: 3.9 | Impact: 5.2
Affected Packages6 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
2Debian▶
CVE-2025-48174: libavif - In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and result...↗2025
Microsoft▶
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.↗2023-08-08