Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-126 Medium 4.5

In libavif before 1.3.0, avifImageRGBToYUV in reformat.c has integer overflows in multiplications...

JLSEC Published
Modified
Severity
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L
Affected Packages
libavif_jll < 1.3.0+0
Aliases / Upstream
GHSA-44mp-2g68-7wvv CVE-2025-48175 EUVD-2025-15403

In libavif before 1.3.0, avifImageRGBToYUV in reformat.c has integer overflows in multiplications involving rgbRowBytes, yRowBytes, uRowBytes, and vRowBytes.

References