In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size.
                
            Metrics
Affected Vendors & Products
References
        History
                    Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Wed, 04 Jun 2025 20:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Aomedia
         Aomedia libavif  | 
|
| CPEs | cpe:2.3:a:aomedia:libavif:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Aomedia
         Aomedia libavif  | 
Fri, 16 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Fri, 16 May 2025 05:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size. | |
| Weaknesses | CWE-190 | |
| References | 
         | 
        
  | 
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: mitre
Published: 2025-05-16T00:00:00.000Z
Updated: 2025-11-03T20:04:42.428Z
Reserved: 2025-05-16T00:00:00.000Z
Link: CVE-2025-48174
Updated: 2025-11-03T20:04:42.428Z
Status : Modified
Published: 2025-05-16T05:15:37.213
Modified: 2025-11-03T20:19:05.993
Link: CVE-2025-48174
No data.