CVE-2025-48174

MEDIUM

Aomedia Libavif < 1.3.0 - Integer Overflow

Title source: rule
STIX 2.1

Description

In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size.

Scores

CVSS v3 4.5
EPSS 0.0036
EPSS Percentile 58.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-190
Status published
Products (1)
aomedia/libavif < 1.3.0
Published May 16, 2025
Tracked Since Feb 18, 2026