CVE-2025-53644: GHSL-2025-057: Heap buffer write in OpenCV - CVE-2025-53644
An uninitialized pointer variable on stack may lead to arbitrary heap buffer write when reading crafted JPEG images.
Other sources
OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53644?
CVE-2025-53644 has a medium severity rating due to the potential for arbitrary heap buffer writes.
How do I fix CVE-2025-53644?
To fix CVE-2025-53644, update OpenCV to version 4.12.0 or later.
What versions of OpenCV are affected by CVE-2025-53644?
OpenCV versions prior to 4.12.0 are affected by CVE-2025-53644.
What kind of issue does CVE-2025-53644 cause?
CVE-2025-53644 causes an uninitialized pointer variable on the stack that may lead to arbitrary heap buffer writes when processing crafted JPEG images.
Is there a known exploit for CVE-2025-53644?
Currently, there are no publicly available exploit details specifically targeting CVE-2025-53644.