CVE-2025-6199: Gdk-pixbuf: uninitialized memory disclosure in gdkpixbuf gif lzw decoder

Published Jun 17, 2025
·
Updated

A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image.

Other sources

Gdk-pixbuf: uninitialized memory disclosure in gdkpixbuf gif lzw decoder

Microsoft

Information Disclosure via uninitialized heap memory exposure in GdkPixbuf’s GIF LZW decoder. Upon encountering an invalid LZW symbol, the decoder incorrectly returns the full buffer length instead of the number of decoded bytes written. This oversight leads to uninitialized memory regions in the output image. A crafted GIF can be used to leak memory contents by processing and then reading back the resulting pixbuf.

Red Hat

Affected Software

11 affected componentsFixes available
GdkPixbuf GdkPixbuf
All of the following
Gnome GdkPixbuf=2.0.0
Any of the following
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Enterprise Linux=10.0
Microsoft cm2 gdk-pixbuf2 2.40.0-7<2.40.0-7
2.40.0-7
Microsoft cbl2 gdk-pixbuf2 2.40.0-6<2.40.0-7
2.40.0-7
Microsoft azl3 gdk-pixbuf2 2.42.10-2<2.42.10-3
2.42.10-3
Microsoft azl3 gdk-pixbuf2 2.42.10-3<2.42.10-3
2.42.10-3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 2.40.0-7
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 2.42.10-3

Event History

Jun 17, 2025
Data Sourced
via Red Hat·12:03 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·02:30 PM
Data Sourced
via MITRE·02:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Jul 11, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-6199?

CVE-2025-6199 has a severity rating that indicates it could lead to potential security risks due to the flawed GIF parser.

2

How do I fix CVE-2025-6199?

To fix CVE-2025-6199, update to the latest version of GdkPixbuf that addresses the GIF parser vulnerability.

3

What systems are affected by CVE-2025-6199?

CVE-2025-6199 affects systems using GdkPixbuf with the LZW decoder for GIF images.

4

What could happen if CVE-2025-6199 is exploited?

If exploited, CVE-2025-6199 may allow attackers to access uninitialized memory, potentially leaking sensitive information.

5

Is there a workaround for CVE-2025-6199?

A temporary workaround for CVE-2025-6199 may involve disabling the use of the GIF decoder until a fix is applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203