Description:
In libavif before 1.3.0, makeRoom in stream.c has an integer overflow
and resultant buffer overflow in stream->offset+size. (CVE-2025-48174)
In libavif before 1.3.0, avifImageRGBToYUV in reformat.c has integer
overflows in multiplications involving rgbRowBytes, yRowBytes,
uRowBytes, and vRowBytes. (CVE-2025-48175)
- https://bugs.mageia.org/show_bug.cgi?id=34336
- https://lists.debian.org/debian-security-announce/2025/msg00094.html
- https://www.cve.org/CVERecord?id=CVE-2025-48174
- https://www.cve.org/CVERecord?id=CVE-2025-48175
- 9/core/libavif-0.11.1-1.1.mga9
Get the latest Linux and open source security news straight to your inbox.