CVE-2025-48174: Integer Overflow
Published May 16, 2025
·Updated
In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size.
Affected Software
2 affected components
libavif libavif<1.3.0
AOMedia Libavif<1.3.0
Remediation
Patch Available
Event History
May 16, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48174?
CVE-2025-48174 is classified as a high severity vulnerability due to the potential for buffer overflow leading to arbitrary code execution.
2
How do I fix CVE-2025-48174?
To fix CVE-2025-48174, upgrade to libavif version 1.3.0 or later where the vulnerability has been addressed.
3
What type of vulnerability is CVE-2025-48174?
CVE-2025-48174 is an integer overflow vulnerability that leads to a buffer overflow in the libavif library.
4
Which versions of libavif are affected by CVE-2025-48174?
CVE-2025-48174 affects all versions of libavif prior to 1.3.0.
5
What occurs as a result of CVE-2025-48174?
The CVE-2025-48174 vulnerability can result in a buffer overflow, potentially allowing for denial of service or remote code execution.