Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-125 Medium 4.5

In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer...

JLSEC Published
Modified
Severity
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L
Affected Packages
libavif_jll < 1.3.0+0
Aliases / Upstream
GHSA-f6x7-5x3c-j3rg CVE-2025-48174 EUVD-2025-15404

In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size.

References