CVE-2025-53644
published 2025-07-17CVE-2025-53644: OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.37%
29.5th percentile
OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | opencv | < opencv 3.2.0+dfsg-1 (bookworm) | opencv 3.2.0+dfsg-1 (bookworm) |
| opencv | opencv | — | — |
| opencv | opencv | >= 0 < 3.2.0+dfsg-1 | 3.2.0+dfsg-1 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-1 | 3.2.0+dfsg-1 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-1 | 3.2.0+dfsg-1 |
| opencv | opencv | >= 0 < 3.2.0+dfsg-1 | 3.2.0+dfsg-1 |
| opencv | opencv | >= 4.10.0 < 4.12.0 | 4.12.0 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.06.6MEDIUMCVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.6MEDIUM
vendor_debian6.6MEDIUM
vendor_redhat6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
opencv: OpenCV use after free
vendor_redhat·2025-07-17·CVSS 6.6
CVE-2025-53644 [MEDIUM] CWE-457 opencv: OpenCV use after free
opencv: OpenCV use after free
OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.
A heap buffer write flaw was found in OpenCV. This vulnerability could result in arbitrary memory overwrites and code execution within the context of a program using OpenCV.
Statement: No Red Hat products or offerings are affected by this vulnerability as the vulnerable code is not present in opencv-3.4 that is shipped with Red Hat Enterprise Linux.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use
Debian
CVE-2025-53644: opencv - OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 hav...
vendor_debian·2025·CVSS 6.6
CVE-2025-53644 [MEDIUM] CVE-2025-53644: opencv - OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 hav...
OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.
Scope: local
bookworm: resolved (fixed in 3.2.0+dfsg-1)
bullseye: resolved (fixed in 3.2.0+dfsg-1)
forky: resolved (fixed in 3.2.0+dfsg-1)
sid: resolved (fixed in 3.2.0+dfsg-1)
trixie: resolved (fixed in 3.2.0+dfsg-1)
OSV
CVE-2025-53644: OpenCV is an Open Source Computer Vision Library
osv·2025-07-17·CVSS 6.6
CVE-2025-53644 [MEDIUM] CVE-2025-53644: OpenCV is an Open Source Computer Vision Library
OpenCV is an Open Source Computer Vision Library. Versions prior to 4.12.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.
OSV
CVE-2025-53644: OpenCV is an Open Source Computer Vision Library
osv·2025-07-17·CVSS 6.6
CVE-2025-53644 [MEDIUM] CVE-2025-53644: OpenCV is an Open Source Computer Vision Library
OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-17
Published