CVE-2025-53644
CRITICALOpenCV 4.10.0-4.11.0 - Arbitrary Heap Buffer Write via Crafted JPEG Image
Title source: llmDescription
OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.
References (4)
Core 4
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://securitylab.github.com/advisories/GHSL-2025-057_OpenCV/
Issue Tracking x_refsource_misc
https://github.com/opencv/opencv/issues/27271
Patch x_refsource_misc
https://github.com/opencv/opencv/commit/a39db41390de546d18962ee1278bd6dbb715f466
Release Notes x_refsource_misc
https://github.com/opencv/opencv/releases/tag/4.12.0
Scores
CVSS v3
9.8
EPSS
0.0036
EPSS Percentile
27.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-457
Status
published
Products (1)
opencv/opencv
4.10.0 - 4.12.0
Published
Jul 17, 2025
Tracked Since
Feb 18, 2026