CVE-2025-44906: Use After Free
Published May 30, 2025
·Updated
jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.
Affected Software
2 affected components
jhead jhead
Jhead Project Jhead=3.08
Event History
May 30, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-44906?
CVE-2025-44906 is classified as a high severity vulnerability due to the potential for exploitation through a heap-use-after-free condition.
2
How do I fix CVE-2025-44906?
To fix CVE-2025-44906, update to the latest version of jhead that addresses this heap-use-after-free vulnerability.
3
What versions of jhead are affected by CVE-2025-44906?
CVE-2025-44906 affects jhead version 3.08 and potentially earlier versions.
4
What are the potential consequences of exploiting CVE-2025-44906?
Exploiting CVE-2025-44906 may lead to arbitrary code execution or application crashes.
5
Is CVE-2025-44906 a zero-day vulnerability?
CVE-2025-44906 is not classified as a zero-day since it has been publicly disclosed and documented.