CVE-2023-45666: GHSL-2023-145_GHSL-2023-151/GHSL-2023-165_GHSL-2023-172: Several memory access violations in stb_image and stb_vorbis
stbimage is a single file MIT licensed library for processing images. It may look like stbiloadgifmain doesn’t give guarantees about the content of output value delays upon failure. Although it sets delays to zero at the beginning, it doesn’t do it in case the image is not recognized as GIF and a call to stbiloadgifmainoutofmem only frees possibly allocated memory in delays without resetting it to zero. Thus it would be fair to say the caller of stbiloadgifmain is responsible to free the allocated memory in delays only if stbiloadgifmain returns a non null value. However at the same time the function may return null value, but fail to free the memory in delays if internally stbiconvertformat is called and fails. Thus the issue may lead to a memory leak if the caller chooses to free delays only when stbiloadgifmain didn’t fail or to a double-free if the delays is always freed
Other sources
stbimage.h and stbvorbis libraries contain several memory access violations of different severity.
— GitHub Security Lab
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-45666?
CVE-2023-45666 is a vulnerability in the stb_image library that may result in a double-free or memory leak in the stbi__load_gif_main function.
What is the severity of CVE-2023-45666?
The severity of CVE-2023-45666 is critical with a CVSS score of 9.8.
How does CVE-2023-45666 impact Nothings Stb Image.h version 2.28?
CVE-2023-45666 affects Nothings Stb Image.h version 2.28, potentially leading to a double-free or memory leak in the stbi__load_gif_main function.
How can I fix CVE-2023-45666?
To fix CVE-2023-45666, it is recommended to update the stb_image library to a patched version provided by the vendor.
Is there any additional information available about CVE-2023-45666?
Yes, you can find more information about CVE-2023-45666 in the references provided, including the advisory and the affected lines of code.